skills/forcedotcom/sf-skills/service-itsm-agentic-setup-cmdb-discovery-configure/Gen Agent Trust Hub
service-itsm-agentic-setup-cmdb-discovery-configure
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill interpolates user-supplied data into SOQL query strings. This creates a surface for SOQL injection if the input is not correctly sanitized.
- Ingestion points: User-provided username or email processed in Step 4 of the workflow.
- Boundary markers: Absent in the query string construction logic.
- Capability inventory: Execution of administrative POST/PATCH requests via the mcp__headless-360__dispatch tool.
- Sanitization: Documentation advises escaping single quotes.
- [PRIVILEGE_ESCALATION]: The skill assigns the 'IT Service Discovery Manager' permission set and license to users. This changes the user's access level in the target Salesforce org. The skill mitigates risks by requiring explicit user confirmation for each modification and verifying prerequisites through org-level permission checks (accessCheck).
Audit Metadata