service-de-channel-settings-configure
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill performs legitimate administrative operations on Salesforce MessagingChannel and MsgChannelLanguageKeyword objects using the official
sfCLI tool. All identified resources and commands align with the expected functionality of a Salesforce management tool. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection by ingesting untrusted data from external sources and user inputs.
- Ingestion points: Data enters the agent context via
sf data queryresults (saved to/tmp/cs-channel.jsonand/tmp/cs-keywords.json) and user-provided inputs for prompts, keywords, and response text. - Boundary markers: The instructions do not define explicit delimiters or instructions for the agent to ignore embedded commands within the ingested Salesforce data.
- Capability inventory: The skill has significant capabilities including
sf data query,sf data update,sf data create,sf project retrieve, andsf project deploy. - Sanitization: The skill provides instructions for XML-escaping response text in
references/channel-settings-facets.mdto prevent deployment failures, which acts as a basic form of sanitization for the Metadata API facet.
Audit Metadata