platform-lsp-integrate
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill describes an interface for processing Apex source code and SOQL query strings, which represents an attack surface for indirect prompt injection from untrusted code.
- Ingestion points: The tools
apex.diagnostics,apex.hover,apex.completion, andvalidate_soqlingest data from local file paths (filePath) and query strings. - Boundary markers: The skill does not define specific prompt boundary markers, but relies on MCP tool response envelopes (
ok,error,hint) to communicate results. - Capability inventory: The skill allows execution of
Bashcommands for CLI fallbacks and local script execution, as well as file reading via theReadtool. - Sanitization: The document focuses on error handling (e.g.,
lsp_disabled,no_org_connected) but does not detail input sanitization for the underlying language servers. - [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute shell commands using the
sfCLI (Salesforce CLI) and a plugin-specific diagnostic script located atbin/lsp-doctor. These are intended for environment verification and fallback mechanisms when the LSP is unavailable.
Audit Metadata