b2c-debug

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill describes using the b2c CLI and npx @salesforce/b2c-cli for debugging purposes. These are official tools for the Salesforce Commerce Cloud ecosystem.
  • [EXTERNAL_DOWNLOADS]: Refers to the official @salesforce/b2c-cli NPM package. As this is an official vendor package from a known organization, it is considered safe for its intended development purpose.
  • [CREDENTIALS_UNSAFE]: The skill correctly advises users to manage secrets using environment variables, dw.json, or .env files, which aligns with security best practices for credential management. It notes that a tool command (b2c setup inspect --unmask) can reveal these secrets, but this is a standard debugging feature for authorized developers.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 04:50 AM
Security Audit — agent-trust-hub — b2c-debug