sf-deploy
Pass
Audited by Gen Agent Trust Hub on Apr 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is focused on standard Salesforce metadata management using the official
sfCLI. It implements a secure 'validate-before-deploy' workflow that minimizes the risk of production environment disruption. - [COMMAND_EXECUTION]: All shell operations are legitimate Salesforce CLI commands used for deployment, retrieval, and status reporting. The skill provides clear guidance on using flags like
--dry-runand--test-levelto ensure safe operations. - [DATA_EXPOSURE]: Documentation includes examples for testing API connectivity (e.g., using
curl), but these examples use placeholders for sensitive parameters and are intended for manual developer validation rather than automated exfiltration. - [EXTERNAL_DOWNLOADS]: External references are limited to well-known community tools and official Salesforce documentation, which are handled neutrally for credit and instructional purposes.
Audit Metadata