service-digital-engagement-deployment-configure
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the Salesforce CLI (
sf) to perform various administrative tasks, including querying record IDs (sf data query), retrieving metadata (sf project retrieve start), making REST API requests (sf api request rest), and updating records (sf data update record). It also executes a local shell scriptscripts/check-api-version.shto validate the environment before proceeding. - [INDIRECT_PROMPT_INJECTION]: The skill implements an update workflow that retrieves existing
EmbeddedServiceConfigmetadata from the Salesforce organization to use as a baseline for modifications. This represents a potential surface where untrusted data from the org could influence the agent's behavior. - Ingestion points: Metadata retrieved from the org using
sf project retrieve start(Phase 2B, Step 10 inSKILL.md). - Boundary markers: No explicit delimiters or instructions to ignore embedded content are used when processing the retrieved XML.
- Capability inventory: The skill has capabilities to write XML files, execute shell scripts, and perform Salesforce CLI operations (data updates and API requests).
- Sanitization: No specific sanitization or validation of the retrieved metadata content is described beyond the standard structure of the
EmbeddedServiceConfigmetadata type.
Audit Metadata