sf-orders
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to use
WebSearchandWebFetchto retrieve live documentation from the internet regarding Salesforce API references. This creates an attack surface where untrusted data from the web could contain instructions meant to influence the agent's behavior. - Ingestion points: Search queries and fetch requests in the "Before Writing Code" section targeting external documentation.
- Boundary markers: No specific delimiters or "ignore instructions" wrappers are provided for the external data.
- Capability inventory: The skill has access to
Write,Edit, andBashtools, which could be misused if the agent obeys instructions embedded in the fetched documentation. - Sanitization: No sanitization logic is present for external content. This is a common architectural risk for skills that fetch external data but is not an active exploit.
Audit Metadata