service-itsm-agentic-setup-cmdb-access-assign
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
dispatchtool provided by theheadless-360server to perform state-changing operations on a Salesforce organization. Specifically, it executesPOSTrequests to assignPermissionSetLicenseAssignandPermissionSetAssignmentrecords. These actions are protected by explicit instructions requiring the agent to confirm the target user and the specific modifications with the human user before proceeding. - [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection as it ingests user-provided text (usernames and emails) to construct SOQL queries. * Ingestion points: User input for name or email in Step 2 of
SKILL.md. * Boundary markers: Absent in query templates. * Capability inventory: Write access to permission assignments via thedispatchtool. * Sanitization: The instructions inreferences/mcp-invocation.mdexplicitly mandate escaping single quotes in user-supplied values to prevent SOQL injection. - [SAFE]: Authentication is managed via the platform's native OAuth JWT binding. The skill does not handle hardcoded credentials, API keys, or org IDs, minimizing the risk of credential exposure.
Audit Metadata