platform-custom-tab-generate

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied data (such as labels, URLs, and descriptions) to populate XML templates for Salesforce Custom Tabs. This creates an attack surface where a user could attempt to inject malicious XML content. However, the skill provides a strict element allowlist and explicitly defines forbidden elements, which acts as a guide for the agent to maintain structural integrity. The risk is considered low and characteristic of data-generation tasks.
  • [SAFE]: The skill instructions are limited to structural metadata generation for Salesforce. No instances of obfuscation, hardcoded credentials, unauthorized network activity, or remote code execution were found. The use of specific motifs and labels follows standard platform development practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:58 AM
Security Audit — agent-trust-hub — platform-custom-tab-generate