platform-dsar-policy-manage

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources, specifically Salesforce object schemas and run logs, which are then used to influence metadata creation and API operations. This surface is mitigated by strict instruction-following regarding root-entity resolution and a dedicated Python validation script (scripts/validate-policy-tree.py) that enforces regex constraints on developer names.\n- [DYNAMIC_EXECUTION]: The skill employs inline Python processing (python3 -c) to filter and project JSON payloads from CLI tool outputs. This technique is used to prevent context window overflow by restricting the volume of ingested data. The execution follows static templates defined within the reference documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 07:35 AM
Security Audit — agent-trust-hub — platform-dsar-policy-manage