sf-b2c-scapi
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a reference for building headless commerce integrations using the official Salesforce Commerce API. It contains no executable code or scripts.
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch live documentation from official Salesforce developer domains and their public GitHub repository. These references target well-known and trusted services for the purpose of verifying current API specifications.
- [CREDENTIALS_UNSAFE]: The documentation explicitly advises developers to store client credentials in environment variables rather than hardcoding them, which aligns with security best practices for secret management.
- [INDIRECT_PROMPT_INJECTION]: The skill defines an attack surface by ingesting external data via documentation searches and fetches.
- Ingestion points: External documentation URLs and search results (SKILL.md).
- Boundary markers: None present.
- Capability inventory: File system access (Read, Write, Edit, Grep, Glob), shell execution (Bash), and network operations (WebSearch, WebFetch).
- Sanitization: No explicit sanitization of fetched documentation content is mentioned. However, since the sources are restricted to trusted official documentation, the risk is minimal.
Audit Metadata