platform-data-manage
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external files, creating a potential vector for indirect prompt injection attacks.
- Ingestion points: Data templates in
assets/csv/andassets/json/, as well as user-provided Apex scripts intended for execution viasf apex run. - Boundary markers: The instructions do not define specific delimiters or instructions for the agent to ignore potentially malicious instructions embedded within the record data.
- Capability inventory: The skill possesses significant capabilities, including creating, updating, and deleting Salesforce records, and executing arbitrary anonymous Apex code in the target environment.
- Sanitization: The skill emphasizes schema and picklist validation, but it lacks specific mechanisms to sanitize or filter text content against instructions directed at the agent.
Audit Metadata