service-omni-channel-inventory-analyze
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/analyze.shscript executes Salesforce CLI (sf) commands, includingsf org displayandsf api request rest. These commands are used to verify org authentication and fetch Omni-Channel configuration data via a POST request to a specific Salesforce headless API endpoint (/services/data/v66.0/headless/invoke). This behavior is consistent with the skill's primary administrative purpose. - [INDIRECT_PROMPT_INJECTION]: The skill processes data fetched from external Salesforce orgs, which constitutes an attack surface for indirect prompt injection.
- Ingestion points: Output from the Salesforce REST API call in
scripts/analyze.shstored inRAW_RESPONSE. - Boundary markers: While no specific text-based delimiters are used to wrap the output for the agent, the script enforces a structured JSON output contract, which provides a logical boundary for the data.
- Capability inventory: The skill has access to the
Bash,Read,Write,Grep, andGlobtools as defined in theallowed-toolsmanifest. - Sanitization: The script uses
jqto validate the JSON structure and extract only predefined fields (e.g.,id,label,routingType), preventing the passage of unvalidated raw response structures to the agent.
Audit Metadata