platform-architecture-analyze
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted code and metadata from Salesforce projects, which could potentially contain malicious instructions intended to influence the analysis outcome.
- Ingestion points: Files such as
sfdx-project.json, Apex classes (.cls), triggers (.trigger), and various metadata XML files are read into the context during the review process (SKILL.md, Step 1 & 2). - Boundary markers: The workflow does not explicitly define isolation markers or instruction-ignoring warnings when reading project file content.
- Capability inventory: The skill utilizes
Bash,Grep, and thesfCLI to perform deep inspection and execute orchestration commands (SKILL.md, Step 2). - Sanitization: Content from the analyzed files is processed directly by grep and other analysis tools without documented sanitization steps.
Audit Metadata