platform-sharing-owd-configure

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied object names and access levels which are interpolated into shell commands. 1. Ingestion points: User input for object API names and sharing access levels throughout SKILL.md. 2. Boundary markers: The instructions do not define specific delimiters for the variables in the command templates. 3. Capability inventory: The skill executes shell commands via the sf CLI, including data queries and metadata deployments. 4. Sanitization: The workflow mandates validation of access levels against references/access_levels.md and requires specific API name formats, which acts as a primary sanitization layer.
  • [COMMAND_EXECUTION]: The skill relies on the sf (Salesforce CLI) tool to perform its primary functions. These commands are standard for Salesforce administration and are executed against the user's authenticated Salesforce environments. The vendor (forcedotcom) is the authoritative source for these tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 07:10 AM
Security Audit — agent-trust-hub — platform-sharing-owd-configure