sf-b2b-experience

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to use WebSearch and WebFetch to retrieve live documentation from external websites such as developer.salesforce.com and help.salesforce.com.
  • Ingestion points: External content fetched via WebFetch and results from WebSearch are incorporated into the agent's context (SKILL.md).
  • Boundary markers: The instructions do not specify explicit delimiters or "ignore embedded instructions" warnings for the external content being processed.
  • Capability inventory: The skill is configured with tools for file system manipulation (Read, Write, Edit, Bash, Grep, Glob) and network access (WebSearch, WebFetch).
  • Sanitization: There is no evidence of sanitization or validation of the external content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM