platform-soql-query
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is authored by forcedotcom (Salesforce) and follows secure design principles. It provides clear guidance and templates for implementing Salesforce security best practices, such as the use of WITH SECURITY_ENFORCED and WITH USER_MODE clauses to respect field-level security and sharing rules.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an ingestion surface for natural language requests and SOQL file contents. It mitigates potential injection risks by implementing a multi-step validation workflow in
scripts/post-tool-validate.py. This script performs static analysis to detect anti-patterns and insecure query shapes before the agent interacts with or executes the queries, effectively maintaining a secure separation between user input and query execution. - [COMMAND_EXECUTION]: The skill documentation and metadata correctly identify and utilize standard command-line tools including the Salesforce CLI (sf), jq, and python3. These tools are used for their intended administrative and development purposes, such as query plan analysis and data formatting, and do not introduce unauthorized execution pathways.
Audit Metadata