platform-metadata-retrieve

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves metadata from external Salesforce orgs, which could serve as a vector for malicious instructions embedded within metadata components such as Apex classes or Custom Objects.
  • Ingestion points: Metadata components retrieved from an org via sf project retrieve start (SKILL.md).
  • Boundary markers: The skill instructions specify returning component counts and file paths rather than processing the file content, establishing a boundary between external data and the agent's operating logic.
  • Capability inventory: The skill uses the Bash tool to execute sf CLI commands for file retrieval and sync operations (SKILL.md).
  • Sanitization: The command includes the --json flag to ensure structured and predictable output for the agent, reducing the risk of parsing errors.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 08:28 PM
Security Audit — agent-trust-hub — platform-metadata-retrieve