service-itsm-agentic-setup-cmdb-configure
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: Verified Infrastructure Access: The skill interacts exclusively with Salesforce-managed endpoints and the
headless-360MCP server. All operations are performed within the context of the user's authenticated session, which is consistent with the vendor's (forcedotcom) infrastructure. - [SAFE]: Administrative Safeguards: The skill implements a secure workflow by enforcing a "read before write" policy. It requires the agent to verify the current state of the organization before attempting any changes and mandates explicit user confirmation before initiating provisioning or feature-enablement tasks.
- [SAFE]: Indirect Injection Mitigation: The instructions explicitly require the agent to sanitize and unescape external strings (such as failure reasons and error messages) retrieved from API responses. This practice mitigates the risk of indirect prompt injection or malicious content being rendered to the user.
- [SAFE]: No Malicious Patterns Detected: A comprehensive scan of the skill's instructions and reference files found no evidence of credential harvesting, unauthorized network exfiltration, obfuscation, or persistence mechanisms.
Audit Metadata