service-itsm-agentic-setup-cmdb-access-assign

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the dispatch tool provided by the headless-360 server to perform state-changing operations on a Salesforce organization. Specifically, it executes POST requests to assign PermissionSetLicenseAssign and PermissionSetAssignment records. These actions are protected by explicit instructions requiring the agent to confirm the target user and the specific modifications with the human user before proceeding.
  • [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection as it ingests user-provided text (usernames and emails) to construct SOQL queries. * Ingestion points: User input for name or email in Step 2 of SKILL.md. * Boundary markers: Absent in query templates. * Capability inventory: Write access to permission assignments via the dispatch tool. * Sanitization: The instructions in references/mcp-invocation.md explicitly mandate escaping single quotes in user-supplied values to prevent SOQL injection.
  • [SAFE]: Authentication is managed via the platform's native OAuth JWT binding. The skill does not handle hardcoded credentials, API keys, or org IDs, minimizing the risk of credential exposure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 05:34 PM
Security Audit — agent-trust-hub — service-itsm-agentic-setup-cmdb-access-assign