service-itsm-agentic-setup-configure

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill functions as a coordination layer for ITSM setup within Salesforce Service Cloud. It utilizes limited-scope tools (Read and AskUserQuestion) and does not perform network operations, file system modifications, or shell command execution.
  • [INDIRECT_PROMPT_INJECTION]: The orchestrator extracts context from chat history and user responses to configure setup tracks. While this ingestion of external data constitutes an attack surface, the skill lacks high-privilege capabilities and limits its actions to information display and internal skill delegation, which effectively mitigates the risk of malicious instruction execution.
  • [DATA_EXFILTRATION]: The instructions demonstrate security-aware design by explicitly directing the agent to use human-readable names and prohibiting the display of Salesforce record IDs in any output, which prevents accidental exposure of internal system identifiers.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 04:35 PM
Security Audit — agent-trust-hub — service-itsm-agentic-setup-configure