service-itsm-agentic-setup-configure
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill functions as a coordination layer for ITSM setup within Salesforce Service Cloud. It utilizes limited-scope tools (Read and AskUserQuestion) and does not perform network operations, file system modifications, or shell command execution.
- [INDIRECT_PROMPT_INJECTION]: The orchestrator extracts context from chat history and user responses to configure setup tracks. While this ingestion of external data constitutes an attack surface, the skill lacks high-privilege capabilities and limits its actions to information display and internal skill delegation, which effectively mitigates the risk of malicious instruction execution.
- [DATA_EXFILTRATION]: The instructions demonstrate security-aware design by explicitly directing the agent to use human-readable names and prohibiting the display of Salesforce record IDs in any output, which prevents accidental exposure of internal system identifiers.
Audit Metadata