deploying-ui-bundle
Pass
Audited by Gen Agent Trust Hub on Apr 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill describes a standard and legitimate deployment workflow for Salesforce projects, adhering to canonical order of operations for metadata and permission management.- [COMMAND_EXECUTION]: The instructions involve running build scripts and metadata deployment tools (such as the Salesforce CLI) which are expected behaviors for the stated purpose of the skill.- [PROMPT_INJECTION]: The skill contains an inherent surface for indirect prompt injection by processing project files like 'sfdx-project.json' or 'package.xml', which is a standard risk for development tools that ingest project metadata.- [EXTERNAL_DOWNLOADS]: Mentions installing dependencies during the build phase, which is standard for UI bundle development using package managers like npm.
Audit Metadata