platform-apex-test-run
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill consumes output from the
sfCLI tool, which creates a potential surface for indirect prompt injection if an attacker can control the content of test failures or messages in the connected Salesforce org. - Ingestion points: The
scripts/parse-test-results.pyscript ingests theTOOL_OUTPUTenvironment variable, which contains the results (JSON or text) of thesf apex run testcommand. - Boundary markers: The script provides structured output headers (e.g.,
📊 APEX TEST RESULTS) and a hardcoded instruction block (🤖 AGENTIC FIX INSTRUCTIONS) to help the agent distinguish between tool output and procedural guidance. - Capability inventory: The skill context allows the agent to read local source files (Apex classes) and invoke a separate skill (
sf-apex) to modify code based on the failure analysis. - Sanitization: The Python script mitigates the risk by truncating failure messages to 200 characters, reducing the potential payload size of any injected instructions.
Audit Metadata