sf-setup
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill directs the agent to fetch documentation from official Salesforce repositories on GitHub and the Salesforce developer portal. These sources are recognized as trusted organizations.
- [INDIRECT_PROMPT_INJECTION]: The skill contains a surface for indirect prompt injection because it instructs the agent to ingest content from external documentation URLs using the WebFetch tool. * Ingestion points: Remote documentation URLs for sfcc-ci, sf CLI, and SFRA project setup mentioned in SKILL.md. * Boundary markers: None explicitly defined to delimit the fetched content. * Capability inventory: Access to command execution (Bash), file system modification (Write, Edit), and file system reading (Read, Grep, Glob). * Sanitization: No explicit validation or filtering logic is provided for the ingested data. Note: This risk is considered negligible as the instruction targets are trusted official documentation sites.
Audit Metadata