service-de-channel-settings-configure

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs legitimate administrative operations on Salesforce MessagingChannel and MsgChannelLanguageKeyword objects using the official sf CLI tool. All identified resources and commands align with the expected functionality of a Salesforce management tool.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection by ingesting untrusted data from external sources and user inputs.
  • Ingestion points: Data enters the agent context via sf data query results (saved to /tmp/cs-channel.json and /tmp/cs-keywords.json) and user-provided inputs for prompts, keywords, and response text.
  • Boundary markers: The instructions do not define explicit delimiters or instructions for the agent to ignore embedded commands within the ingested Salesforce data.
  • Capability inventory: The skill has significant capabilities including sf data query, sf data update, sf data create, sf project retrieve, and sf project deploy.
  • Sanitization: The skill provides instructions for XML-escaping response text in references/channel-settings-facets.md to prevent deployment failures, which acts as a basic form of sanitization for the Metadata API facet.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 05:34 PM
Security Audit — agent-trust-hub — service-de-channel-settings-configure