b2c-debug
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill describes using the
b2cCLI andnpx @salesforce/b2c-clifor debugging purposes. These are official tools for the Salesforce Commerce Cloud ecosystem. - [EXTERNAL_DOWNLOADS]: Refers to the official
@salesforce/b2c-cliNPM package. As this is an official vendor package from a known organization, it is considered safe for its intended development purpose. - [CREDENTIALS_UNSAFE]: The skill correctly advises users to manage secrets using environment variables,
dw.json, or.envfiles, which aligns with security best practices for credential management. It notes that a tool command (b2c setup inspect --unmask) can reveal these secrets, but this is a standard debugging feature for authorized developers.
Audit Metadata