sf-einstein

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The instructions direct the agent to retrieve live documentation and API references from external web sources using WebSearch and WebFetch tools. This creates a surface where an attacker could host malicious content that might influence the agent's code generation or file system operations.
  • Ingestion points: Web search and fetch operations for Salesforce documentation (SKILL.md).
  • Boundary markers: Absent; the skill does not provide instructions to delimit or treat the external data as untrusted.
  • Capability inventory: The agent has access to Write, Edit, and Bash tools, which could be misused if the agent follows instructions found within external content.
  • Sanitization: No sanitization or validation of the retrieved web content is specified before the agent acts upon it.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM