service-itsm-agentic-setup-cmdb-configure
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed for administrative configuration of Salesforce Service Cloud ITSM and does not contain any malicious patterns. It adheres to a secure-by-default posture by delegating authentication to the platform's OAuth session and avoiding the handling of raw credentials.
- [INDIRECT_PROMPT_INJECTION]: While the skill ingests data from external Salesforce API responses (such as provisioning status and error reasons), it includes explicit instructions to sanitize this data. The agent is directed to unescape HTML entities, strip markup, and translate technical error codes into plain language before presenting them to the user, effectively mitigating risks associated with instructions embedded in external data.
- [COMMAND_EXECUTION]: The skill uses specialized MCP tools (headless-360) to perform HTTP operations against Salesforce Connect APIs. These actions are limited to the intended scope of the skill (feature enablement and tenant provisioning) and require explicit user confirmation for every state-changing request (POST), preventing unauthorized modifications.
- [DATA_EXPOSURE_AND_EXFILTRATION]: All network operations are directed towards official Salesforce API endpoints through a vendor-hosted MCP server. No sensitive files are accessed, and no data is exfiltrated to unverified third-party domains.
Audit Metadata