sf-b2c-ocapi

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow that ingests external documentation to provide the agent with current context.
  • Ingestion points: The skill instructs the agent to use WebSearch and WebFetch to retrieve reference documents and migration guides from developer.salesforce.com.
  • Boundary markers: The instructions do not define explicit delimiters or isolation markers for the ingested external content.
  • Capability inventory: The agent is granted access to tools such as Bash, Write, and Edit, which are standard for development tasks but represent a potential target for instructions embedded in external data.
  • Sanitization: No explicit sanitization or validation logic is specified for the fetched documentation.
  • Trust Context: The use of official Salesforce developer domains is a standard operational requirement for this skill's stated purpose and is considered a safe practice.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:34 PM