salesforce-developer

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The CI/CD workflow examples in references/deployment-devops.md download the official Salesforce CLI tool from developer.salesforce.com. This is a well-known and trusted source for Salesforce development tools.
  • [REMOTE_CODE_EXECUTION]: The skill documents standard practices for executing code on the Salesforce platform, including Apex triggers, batch jobs, and anonymous scripts. All examples follow best practices, such as using WITH SECURITY_ENFORCED in queries to respect field-level security and using String.escapeSingleQuotes for dynamic SOQL to prevent injection.
  • [DATA_EXFILTRATION]: Integration patterns in references/integration-patterns.md demonstrate the use of Named Credentials for secure communication with external APIs. This is the recommended Salesforce security practice to avoid hardcoding credentials or exposing sensitive data during callouts.
  • [SAFE]: The skill correctly handles sensitive configurations in DevOps examples by referencing environment secrets (e.g., ${{ secrets.SFDX_AUTH_URL }}) rather than providing actual credentials. All code snippets provided are pedagogical examples of legitimate Salesforce development patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 08:51 PM
Security Audit — agent-trust-hub — salesforce-developer