service-omni-attribute-routing-configure

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/configure-and-report.sh executes Salesforce CLI (sf) commands to manage routing metadata. These commands are parameterised and targeted at the user's authenticated Salesforce environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill manages potential data injection surfaces through validation and safe interpolation.
  • Ingestion points: Salesforce Tooling API responses and record query results in scripts/configure-and-report.sh.
  • Boundary markers: Implements an organization type check (safe_to_write) to block modifications in production customer environments.
  • Capability inventory: Performs Tooling API CRUD operations using sf api request rest and sf data delete.
  • Sanitization: Uses jq with argument binding (--arg) to escape data when building JSON payloads and validates inputs like DeveloperName and field using regular expressions.
  • [SAFE]: The use of subprocess.run in scripts/tests/test_attribute_routing_contracts.py is limited to a controlled unit testing environment and does not pose a threat to the execution environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 05:34 PM
Security Audit — agent-trust-hub — service-omni-attribute-routing-configure