service-agentforce-contact-center-coordinate
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes multiple shell scripts that wrap the Salesforce CLI (sf) to perform administrative tasks including user creation (sf org create agent-user), metadata deployment (sf project deploy start), and agent publication (sf agent publish).
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface where user-provided inputs are used to generate executable metadata.
- Ingestion points: User inputs for agent name, description, and company name are collected via AskUserQuestion in Step 9 of the workflow defined in SKILL.md.
- Boundary markers: The skill lacks explicit "ignore embedded instructions" prompts within the RoutingFlow XML templates located in the assets directory.
- Capability inventory: The skill context has capabilities to deploy metadata using sf project deploy start and interact with Salesforce REST APIs via sf api request rest as seen in the various bash scripts.
- Sanitization: The scripts/lib.sh file includes an xml_escape function which is applied to user-provided strings before interpolation into the RoutingFlow XML templates in scripts/create-routing-flows.sh.
Audit Metadata