sf-setup

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill directs the agent to fetch documentation from official Salesforce repositories on GitHub and the Salesforce developer portal. These sources are recognized as trusted organizations.
  • [INDIRECT_PROMPT_INJECTION]: The skill contains a surface for indirect prompt injection because it instructs the agent to ingest content from external documentation URLs using the WebFetch tool. * Ingestion points: Remote documentation URLs for sfcc-ci, sf CLI, and SFRA project setup mentioned in SKILL.md. * Boundary markers: None explicitly defined to delimit the fetched content. * Capability inventory: Access to command execution (Bash), file system modification (Write, Edit), and file system reading (Read, Grep, Glob). * Sanitization: No explicit validation or filtering logic is provided for the ingested data. Note: This risk is considered negligible as the instruction targets are trusted official documentation sites.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:34 PM