platform-metadata-retrieve
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill retrieves metadata from external Salesforce orgs, which could serve as a vector for malicious instructions embedded within metadata components such as Apex classes or Custom Objects.
- Ingestion points: Metadata components retrieved from an org via
sf project retrieve start(SKILL.md). - Boundary markers: The skill instructions specify returning component counts and file paths rather than processing the file content, establishing a boundary between external data and the agent's operating logic.
- Capability inventory: The skill uses the Bash tool to execute
sfCLI commands for file retrieval and sync operations (SKILL.md). - Sanitization: The command includes the
--jsonflag to ensure structured and predictable output for the agent, reducing the risk of parsing errors.
Audit Metadata