sfnext-custom-apis

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security risks were identified in this skill. The instructions and code examples provided are standard practices for developing and consuming custom APIs within the Salesforce Commerce Cloud ecosystem.
  • [COMMAND_EXECUTION]: The skill documents the use of the b2c CLI tool for common development tasks such as code deployment (b2c code deploy), checking API status (b2c scapi custom status), and managing storefront clients (b2c sfnext scapi add). These are legitimate developer operations for the target platform.
  • [PROMPT_INJECTION]: No attempts to override agent behavior, bypass safety guidelines, or extract system prompts were detected. The instructional language is strictly scoped to technical guidance for Salesforce development.
  • [DATA_EXFILTRATION]: No sensitive file access, hardcoded credentials, or unauthorized network operations were found. Placeholders are used appropriately for sensitive parameters like customer IDs.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 05:30 AM
Security Audit — agent-trust-hub — sfnext-custom-apis