platform-custom-setting-generate

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows security best practices for the Salesforce platform. It explicitly warns against storing sensitive information like API keys or passwords in custom settings and recommends using Named Credentials instead. It also incorporates a 'no-silent-downgrade' rule to prevent unintended exposure of components if visibility settings fail during deployment.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided metadata descriptions to generate XML and CLI commands. While this represents a potential surface for indirect injection, the risk is minimized by the structured nature of the generated XML and the specific instructions to use proper quoting for shell commands. The impact is assessed as safe given the context of the primary task.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 09:54 AM
Security Audit — agent-trust-hub — platform-custom-setting-generate