platform-apex-test-run

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill consumes output from the sf CLI tool, which creates a potential surface for indirect prompt injection if an attacker can control the content of test failures or messages in the connected Salesforce org.
  • Ingestion points: The scripts/parse-test-results.py script ingests the TOOL_OUTPUT environment variable, which contains the results (JSON or text) of the sf apex run test command.
  • Boundary markers: The script provides structured output headers (e.g., 📊 APEX TEST RESULTS) and a hardcoded instruction block (🤖 AGENTIC FIX INSTRUCTIONS) to help the agent distinguish between tool output and procedural guidance.
  • Capability inventory: The skill context allows the agent to read local source files (Apex classes) and invoke a separate skill (sf-apex) to modify code based on the failure analysis.
  • Sanitization: The Python script mitigates the risk by truncating failure messages to 200 characters, reducing the potential payload size of any injected instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 08:26 PM
Security Audit — agent-trust-hub — platform-apex-test-run