platform-data-manage

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external files, creating a potential vector for indirect prompt injection attacks.
  • Ingestion points: Data templates in assets/csv/ and assets/json/, as well as user-provided Apex scripts intended for execution via sf apex run.
  • Boundary markers: The instructions do not define specific delimiters or instructions for the agent to ignore potentially malicious instructions embedded within the record data.
  • Capability inventory: The skill possesses significant capabilities, including creating, updating, and deleting Salesforce records, and executing arbitrary anonymous Apex code in the target environment.
  • Sanitization: The skill emphasizes schema and picklist validation, but it lacks specific mechanisms to sanitize or filter text content against instructions directed at the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:42 AM
Security Audit — agent-trust-hub — platform-data-manage