platform-manifest-generate

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits a theoretical indirect prompt injection attack surface as it processes external configuration and metadata files. 1. Ingestion points: Reads from sfdx-project.json, scans local source directories, and introspects Salesforce orgs via CLI tools. 2. Boundary markers: No explicit delimiters or boundary instructions are used for the ingested content. 3. Capability inventory: Performs subprocess calls via the sf CLI and file-write operations through the Write tool. 4. Sanitization: No explicit sanitization or validation of ingested metadata is mentioned. This surface is necessary for the skill's primary function and does not indicate malicious intent.
  • [SAFE]: No other security concerns were detected. The skill follows standard Salesforce development practices and uses legitimate vendor-provided tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 08:50 AM
Security Audit — agent-trust-hub — platform-manifest-generate