salesloft-ci-integration
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it is designed to ingest and process untrusted repository data while possessing the capability to modify files.
- Ingestion points: Uses
Read,Glob, andGreptools to inspect repository workflows, adapters, and source code. - Boundary markers: No specific instructions are provided to the agent to ignore or delimit instructions found within the repository files being analyzed.
- Capability inventory: The skill is granted
WriteandEditpermissions in itsallowed-toolsto modify CI configurations and repository files. - Sanitization: While the instructions emphasize using "sanitized fixtures," there is no explicit sanitization for the agent's interpretation of code comments or strings as instructions.
- [SAFE]: The skill promotes security best practices for CI/CD environments, including the use of offline contract fixtures to avoid live credential usage in untrusted forks and explicit requirements for secret redaction in logs.
- [SAFE]: All external documentation links and resource references target official Salesloft developer domains.
Audit Metadata