platform-lsp-integrate

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill describes an interface for processing Apex source code and SOQL query strings, which represents an attack surface for indirect prompt injection from untrusted code.
  • Ingestion points: The tools apex.diagnostics, apex.hover, apex.completion, and validate_soql ingest data from local file paths (filePath) and query strings.
  • Boundary markers: The skill does not define specific prompt boundary markers, but relies on MCP tool response envelopes (ok, error, hint) to communicate results.
  • Capability inventory: The skill allows execution of Bash commands for CLI fallbacks and local script execution, as well as file reading via the Read tool.
  • Sanitization: The document focuses on error handling (e.g., lsp_disabled, no_org_connected) but does not detail input sanitization for the underlying language servers.
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute shell commands using the sf CLI (Salesforce CLI) and a plugin-specific diagnostic script located at bin/lsp-doctor. These are intended for environment verification and fallback mechanisms when the LSP is unavailable.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 01:16 PM
Security Audit — agent-trust-hub — platform-lsp-integrate