service-helpagent-coordinate

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: In 'assets/help-agent-spec.md', the skill specifies 'silent pre-flight' checks for internal verification steps. This is a procedural UX pattern to avoid verbose success messaging during system readiness checks (licensing, permissions, activation) and does not bypass safety as errors are still required to be reported to the user.
  • [COMMAND_EXECUTION]: The skill utilizes the Salesforce CLI ('sf') and 'curl' to automate metadata operations and API calls. These are standard tools for Salesforce administration and are used within the scope of the skill's agent-coordination purpose.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with the 'api.salesforce.com' domain to perform Connect API operations. This is a well-known service associated with the skill's vendor (Salesforce) and is necessary for provisioning Agentforce agents.
  • [DATA_EXFILTRATION]: The skill accesses Salesforce Knowledge and org metadata. These operations are performed within the user's authenticated session for the purpose of grounding the agent and configuring its environment, with no evidence of unauthorized external data transfer.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 09:29 PM
Security Audit — agent-trust-hub — service-helpagent-coordinate