platform-metadata-deploy
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on the sf CLI v2 to perform Salesforce operations, including sf project deploy, sf project retrieve, and sf agent commands.
- [EXTERNAL_DOWNLOADS]: The skill documentation describes network interactions with Salesforce domains (*.salesforce.com) for API connectivity and OAuth token management. These are well-known and trusted services associated with the skill's primary purpose.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection. 1. Ingestion points: Local metadata source files in the force-app directory and deployment result summaries from the Salesforce org. 2. Boundary markers: The instructions do not define explicit delimiters or warnings for the agent to ignore instructions embedded within the metadata. 3. Capability inventory: The skill can deploy metadata, retrieve data, and execute code in the org. 4. Sanitization: No specific filtering of external content is implemented.
Audit Metadata