service-omni-channel-inventory-analyze

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/analyze.sh script executes Salesforce CLI (sf) commands, including sf org display and sf api request rest. These commands are used to verify org authentication and fetch Omni-Channel configuration data via a POST request to a specific Salesforce headless API endpoint (/services/data/v66.0/headless/invoke). This behavior is consistent with the skill's primary administrative purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data fetched from external Salesforce orgs, which constitutes an attack surface for indirect prompt injection.
  • Ingestion points: Output from the Salesforce REST API call in scripts/analyze.sh stored in RAW_RESPONSE.
  • Boundary markers: While no specific text-based delimiters are used to wrap the output for the agent, the script enforces a structured JSON output contract, which provides a logical boundary for the data.
  • Capability inventory: The skill has access to the Bash, Read, Write, Grep, and Glob tools as defined in the allowed-tools manifest.
  • Sanitization: The script uses jq to validate the JSON structure and extract only predefined fields (e.g., id, label, routingType), preventing the passage of unvalidated raw response structures to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 05:34 PM
Security Audit — agent-trust-hub — service-omni-channel-inventory-analyze