platform-capability-search
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from user inputs and external plugin metadata.
- Ingestion points: User task descriptions are passed to the
plugin-matchscript, and registry descriptions are read as tool output. - Boundary markers: The instructions explicitly warn the agent to treat descriptions as untrusted metadata and never execute commands found within them.
- Capability inventory: Command execution is limited to the
sf-contextscript. - Sanitization: The skill mandates that user input be passed exactly as given and warns against natural language interpolation.
- [COMMAND_EXECUTION]: The skill uses the Bash tool to execute fixed vendor-provided scripts located in the plugin root directory for Salesforce environment analysis.
Audit Metadata