experience-aura-lwc-migrate
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is authored by the expected vendor and performs static analysis for code migration purposes.- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted Aura source files to generate a migration blueprint. * Ingestion points: .cmp, .controller.js, .helper.js, .renderer.js, .css, .design, .evt, .intf files. * Boundary markers: Not explicitly defined for the PRD output. * Capability inventory: Local file reading and writing of blueprint files. * Sanitization: The skill employs an architectural analysis workflow (eight expert lenses) to abstract implementation details into functional descriptions, reducing the potential for direct execution of malicious instructions.- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill accesses files within the project workspace and internal libraries in node_modules/@sfdc-internal/adk-knowledge. These operations are restricted to the local environment and are necessary for the skill's functionality, with no network activity detected.
Audit Metadata