sf-b2c-scapi

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a reference for building headless commerce integrations using the official Salesforce Commerce API. It contains no executable code or scripts.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch live documentation from official Salesforce developer domains and their public GitHub repository. These references target well-known and trusted services for the purpose of verifying current API specifications.
  • [CREDENTIALS_UNSAFE]: The documentation explicitly advises developers to store client credentials in environment variables rather than hardcoding them, which aligns with security best practices for secret management.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines an attack surface by ingesting external data via documentation searches and fetches.
  • Ingestion points: External documentation URLs and search results (SKILL.md).
  • Boundary markers: None present.
  • Capability inventory: File system access (Read, Write, Edit, Grep, Glob), shell execution (Bash), and network operations (WebSearch, WebFetch).
  • Sanitization: No explicit sanitization of fetched documentation content is mentioned. However, since the sources are restricted to trusted official documentation, the risk is minimal.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM