sf-b2c-isml
Pass
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a technical guide for developing Salesforce B2C Commerce templates, providing detailed documentation on syntax and platform-specific features.
- [SAFE]: Instructions promote security best practices, specifically emphasizing the use of the
<isprint>tag with appropriate encoding modes to prevent Cross-Site Scripting (XSS) vulnerabilities. - [SAFE]: The skill instructs the agent to fetch updated documentation from Salesforce using the
WebFetchtool. This reference to a well-known service is used for maintaining up-to-date technical knowledge and does not involve sensitive data access. - [SAFE]: No malicious prompt injection patterns, data exfiltration attempts, or obfuscated content were detected within the skill instructions.
- [SAFE]: While the
Bashtool is listed in theallowed-toolsconfiguration, the skill does not contain any executable scripts or instructions that perform dangerous shell operations.
Audit Metadata