sf-docs
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external web sources which could contain malicious instructions.\n
- Ingestion points: The script
extract_salesforce_doc.pyfetches and extracts text from external URLs, primarily from Salesforce-owned domains like developer.salesforce.com and help.salesforce.com.\n - Boundary markers: The
SKILL.mdfile defines strict 'Acceptance Rules' and 'Rejection Rules' requiring exact concept matching, which helps mitigate accidental obedience to injected content.\n - Capability inventory: The skill possesses network read capabilities (via Playwright) and can execute managed shell commands for runtime bootstrapping.\n
- Sanitization: While the scripts normalize and clean extracted text, they do not provide cryptographic validation or instruction-filtering sanitization of the retrieved content.\n- [DYNAMIC_EXECUTION]: The
scripts/runtime_bootstrap.pymodule usesos.execve()for process replacement to manage its local environment.\n - Evidence: The
maybe_reexec_in_sf_docs_runtimefunction detects if the script is running outside its dedicated virtual environment and usesos.execveto restart the process using a Python interpreter located in~/.claude/.sf-docs-runtime/venv.\n- [COMMAND_EXECUTION]: The runtime management logic executes a Python interpreter from a path determined dynamically at runtime.\n- [EXTERNAL_DOWNLOADS]: The skill is designed to work with an installer that downloads the Playwright Chromium browser and associated Python packages into a hidden local directory.
Audit Metadata