service-helpagent-coordinate

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill contains explicit instructions in SKILL.md and assets/help-agent-spec.md to conceal specific actions from the user. For instance, the agent is directed to run readiness checks and a pre-flight inventory silently, with strict directives not to announce these phases or print status messages unless a failure occurs. This design choice reduces transparency regarding the agent's background execution of shell commands and org data queries.
  • [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests untrusted data from Salesforce Knowledge articles and user-provided files for agent grounding.
  • Ingestion points: Content from Salesforce Knowledge articles, user-uploaded files, and Data Category Group metadata.
  • Boundary markers: The instructions do not define specific delimiters or "ignore instructions" warnings for the grounded content when building the agent configuration.
  • Capability inventory: The skill uses the Bash tool to perform extensive operations via the Salesforce CLI (sf), Python scripts, and file system writes.
  • Sanitization: There is no explicit sanitization or filtering of the external grounding data before it is processed by the agent.
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute complex shell scripts, Salesforce CLI commands (sf data query, sf data create record, sf org assign permset), and Python scripts to analyze org readiness and deploy metadata.
  • [EXTERNAL_DOWNLOADS]: The README.md includes setup instructions to install the forcedotcom/sf-skills package using npx. As the author of the skill is forcedotcom, this package is a vendor-managed resource.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 05:35 PM
Security Audit — agent-trust-hub — service-helpagent-coordinate