sf-performance
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides legitimate instructions for optimizing Salesforce B2C and B2B Commerce platforms and does not include any obfuscation, remote code execution, or unauthorized data access patterns.
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to fetch external data via WebSearch and WebFetch, which is a potential surface for indirect prompt injection. 1. Ingestion points: Search results and external documentation pages from developer.salesforce.com and web.dev. 2. Boundary markers: Absent for the external content. 3. Capability inventory: Bash, Write, Edit, Read, Grep, Glob. 4. Sanitization: Absent. The targeted domains are recognized as well-known technology and developer services, which significantly mitigates risk.
Audit Metadata