sf-performance

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides legitimate instructions for optimizing Salesforce B2C and B2B Commerce platforms and does not include any obfuscation, remote code execution, or unauthorized data access patterns.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to fetch external data via WebSearch and WebFetch, which is a potential surface for indirect prompt injection. 1. Ingestion points: Search results and external documentation pages from developer.salesforce.com and web.dev. 2. Boundary markers: Absent for the external content. 3. Capability inventory: Bash, Write, Edit, Read, Grep, Glob. 4. Sanitization: Absent. The targeted domains are recognized as well-known technology and developer services, which significantly mitigates risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:34 PM