b2c-custom-api-development

Pass

Audited by Gen Agent Trust Hub on Apr 15, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches and executes the official Salesforce B2C CLI tool using npx for deployment and cartridge management.
  • [COMMAND_EXECUTION]: Provides instructions for using the b2c command-line utility to deploy code, check endpoint registration status, and manage authentication clients.
  • [DATA_EXFILTRATION]: Documents testing procedures that use curl to interact with official Salesforce Commerce Cloud and Account Manager API endpoints for token acquisition and endpoint verification.
  • [PROMPT_INJECTION]: Identifies a data ingestion surface where Custom APIs process external HTTP input. Ingestion points in script.js include request.getHttpParameterMap, request.getSCAPIPathParameters, and request.httpParameterMap.requestBodyAsString. The skill guides developers to use OAS 3.0 schema validation in schema.yaml as a boundary measure to validate input. Capability inventory includes the ability to make outbound network calls via the platform's LocalServiceRegistry.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 15, 2026, 04:00 PM
Security Audit — agent-trust-hub — b2c-custom-api-development