platform-architecture-analyze

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed as a passive auditor, using standard tools to detect security and performance risks in Salesforce code and metadata without modifying the project or its environment.- [COMMAND_EXECUTION]: Local shell commands like grep, find, and the Salesforce CLI (sf) are employed to scan project files for specific patterns. These commands are constrained to discovery and reporting tasks.- [PROMPT_INJECTION]: While the skill ingests untrusted code from the repository, its use of hardcoded analysis patterns and delegation to dedicated scanner tools minimizes the risk of indirect prompt injection. (Category 8: Ingestion points: Salesforce project files; Capability inventory: Bash, Grep, sf CLI; Sanitization: Not applicable for pattern matching; Boundary markers: None).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 07:09 AM
Security Audit — agent-trust-hub — platform-architecture-analyze