sf-b2c-ocapi
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow that ingests external documentation to provide the agent with current context.
- Ingestion points: The skill instructs the agent to use WebSearch and WebFetch to retrieve reference documents and migration guides from developer.salesforce.com.
- Boundary markers: The instructions do not define explicit delimiters or isolation markers for the ingested external content.
- Capability inventory: The agent is granted access to tools such as Bash, Write, and Edit, which are standard for development tasks but represent a potential target for instructions embedded in external data.
- Sanitization: No explicit sanitization or validation logic is specified for the fetched documentation.
- Trust Context: The use of official Salesforce developer domains is a standard operational requirement for this skill's stated purpose and is considered a safe practice.
Audit Metadata