integration-eventing-subscription-configure

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill focuses on generating and managing XML metadata files for Salesforce. All activities, including file generation and the use of the Salesforce CLI (sf), are standard development practices within the Salesforce ecosystem.
  • [COMMAND_EXECUTION]: The skill provides instructions for the user to execute standard Salesforce CLI commands for deployment and tooling API queries. These commands are localized to the user's environment and target-org alias provided by the user.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied strings such as DeveloperName, label, and topicName. While these are interpolated into XML files, the skill defines clear validation constraints (e.g., alphanumeric restrictions for names and specific enums for state and replay presets), which mitigates the risk of malformed metadata or injection attempts.
  • [DATA_EXPOSURE]: The skill does not access sensitive local files or hardcoded credentials. It interacts with Salesforce metadata which is the intended purpose of the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 03:37 AM
Security Audit — agent-trust-hub — integration-eventing-subscription-configure