platform-architecture-analyze

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted code and metadata from Salesforce projects, which could potentially contain malicious instructions intended to influence the analysis outcome.
  • Ingestion points: Files such as sfdx-project.json, Apex classes (.cls), triggers (.trigger), and various metadata XML files are read into the context during the review process (SKILL.md, Step 1 & 2).
  • Boundary markers: The workflow does not explicitly define isolation markers or instruction-ignoring warnings when reading project file content.
  • Capability inventory: The skill utilizes Bash, Grep, and the sf CLI to perform deep inspection and execute orchestration commands (SKILL.md, Step 2).
  • Sanitization: Content from the analyzed files is processed directly by grep and other analysis tools without documented sanitization steps.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 08:21 PM
Security Audit — agent-trust-hub — platform-architecture-analyze