platform-flexipage-generate
Fail
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/scan-lwc-components.shscript is vulnerable to shell command injection. The script processes user-supplied query strings using anechocommand inside a subshell expansion:$(echo "$QUERY" | tr ... ). If the query string contains shell metacharacters like$()or backticks, the bash shell will evaluate and execute them as commands during the variable expansion phase. - [COMMAND_EXECUTION]: The
scripts/resolve-component-instructions.shscript contains a similar command injection vulnerability. It evaluates the component definition argument usingechoinside a subshell:$(echo "$COMPONENT" | sed ... ). Maliciously crafted component names can trigger arbitrary command execution on the host system. - [EXTERNAL_DOWNLOADS]: The skill installs the official Salesforce CLI
templatesplugin to support FlexiPage generation tasks. This is a reference to a well-known service functionality. - [INDIRECT_PROMPT_INJECTION]: The skill's primary workflow involves transforming natural language user intent into executable Salesforce metadata and Lightning Web Component (LWC) source code, which represents an attack surface for indirect prompt injection.
- Ingestion points: User utterances describing requested components and page configurations are parsed to identify intents in Step 1 of the Adding Components workflow.
- Boundary markers: There are no explicit instructions for the agent to use delimiters or ignore embedded instructions when interpolating user intent into tool arguments or generated files.
- Capability inventory: The skill uses the
Bashtool to executesf project deploy(metadata deployment),sf template generate(file generation), and performs local file system write operations for LWC generation. - Sanitization: The skill does not provide mechanisms for validating or escaping user-provided names, labels, or descriptions before they are used in CLI commands or generated source code, potentially allowing a user to inject malicious metadata or code properties.
Recommendations
- AI detected serious security threats
Audit Metadata