b2c-import-set-migrations

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill provides usage guidelines for the @salesforce/b2c-cli tool, which is a legitimate resource from the identified author salesforcecommercecloud.
  • [DATA_EXPOSURE]: The documentation explicitly warns users to remove sensitive information, such as secrets and encrypted passwords, from site archives before committing them to a repository or applying them to instances.
  • [COMMAND_EXECUTION]: The skill describes shell commands for b2c job import-set. These are standard functional commands for the tool's intended purpose and do not show signs of malicious injection or unauthorized privilege escalation.
  • [INDIRECT_PROMPT_INJECTION]: While the tool processes external migration archives (XML), this is the primary function of the utility. The skill itself does not ingest untrusted data into the LLM context in a way that would facilitate prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 10:01 AM
Security Audit — agent-trust-hub — b2c-import-set-migrations