platform-trust-archive-manage
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is authored by Salesforce (forcedotcom), a trusted vendor. All API interactions and resource references target official Salesforce platform infrastructure, ensuring that data stays within the authenticated environment.
- [SAFE]: The instructions accurately detail the specific user permissions required for various archive operations (e.g., UnarchiveSdk, Rtbf, ArchiveAnalyzer), reinforcing the platform's native security model rather than attempting to bypass it.
- [SAFE]: No malicious patterns such as prompt injection, obfuscation, or unauthorized data exfiltration were identified. The use of the Salesforce CLI ('sf') for API requests is a standard, expected practice for this domain.
- [SAFE]: The skill documents the potential for indirect prompt injection from archived records and logs as a known data ingestion surface, but relies on standard platform guardrails and authenticated access rather than introducing new vulnerabilities.
Audit Metadata