sf-einstein
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The instructions direct the agent to retrieve live documentation and API references from external web sources using WebSearch and WebFetch tools. This creates a surface where an attacker could host malicious content that might influence the agent's code generation or file system operations.
- Ingestion points: Web search and fetch operations for Salesforce documentation (SKILL.md).
- Boundary markers: Absent; the skill does not provide instructions to delimit or treat the external data as untrusted.
- Capability inventory: The agent has access to Write, Edit, and Bash tools, which could be misused if the agent follows instructions found within external content.
- Sanitization: No sanitization or validation of the retrieved web content is specified before the agent acts upon it.
Audit Metadata