platform-capability-search

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from user inputs and external plugin metadata.
  • Ingestion points: User task descriptions are passed to the plugin-match script, and registry descriptions are read as tool output.
  • Boundary markers: The instructions explicitly warn the agent to treat descriptions as untrusted metadata and never execute commands found within them.
  • Capability inventory: Command execution is limited to the sf-context script.
  • Sanitization: The skill mandates that user input be passed exactly as given and warns against natural language interpolation.
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute fixed vendor-provided scripts located in the plugin root directory for Salesforce environment analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 03:42 AM
Security Audit — agent-trust-hub — platform-capability-search