skills/jaganpro/sf-skills/sf-docs/Gen Agent Trust Hub

sf-docs

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external web sources which could contain malicious instructions.\n
  • Ingestion points: The script extract_salesforce_doc.py fetches and extracts text from external URLs, primarily from Salesforce-owned domains like developer.salesforce.com and help.salesforce.com.\n
  • Boundary markers: The SKILL.md file defines strict 'Acceptance Rules' and 'Rejection Rules' requiring exact concept matching, which helps mitigate accidental obedience to injected content.\n
  • Capability inventory: The skill possesses network read capabilities (via Playwright) and can execute managed shell commands for runtime bootstrapping.\n
  • Sanitization: While the scripts normalize and clean extracted text, they do not provide cryptographic validation or instruction-filtering sanitization of the retrieved content.\n- [DYNAMIC_EXECUTION]: The scripts/runtime_bootstrap.py module uses os.execve() for process replacement to manage its local environment.\n
  • Evidence: The maybe_reexec_in_sf_docs_runtime function detects if the script is running outside its dedicated virtual environment and uses os.execve to restart the process using a Python interpreter located in ~/.claude/.sf-docs-runtime/venv.\n- [COMMAND_EXECUTION]: The runtime management logic executes a Python interpreter from a path determined dynamically at runtime.\n- [EXTERNAL_DOWNLOADS]: The skill is designed to work with an installer that downloads the Playwright Chromium browser and associated Python packages into a hidden local directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:48 PM