sf-ai-agentforce
Pass
Audited by Gen Agent Trust Hub on Mar 14, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [SAFE]: The skill serves as a comprehensive reference for Salesforce Agentforce development. It utilizes official platform metadata types and native Salesforce APIs without introducing any malicious code or unsafe execution patterns.\n- [PROMPT_INJECTION]: The skill provides detailed guidance on authoring PromptTemplates and Agent Script instructions. It explicitly includes security best practices for handling untrusted data, such as using boundary markers like '--- KNOWLEDGE CONTEXT ---' and specific grounding instructions to prevent indirect prompt injection.\n- [EXTERNAL_DOWNLOADS]: References within the skill point to the official Salesforce CLI and associated developer tools and skills from the same author. These are standard resources for Salesforce development and are used for legitimate metadata management and deployment.\n- [COMMAND_EXECUTION]: The documentation includes instructions for using the Salesforce CLI (
sf) to manage agent lifecycles and deploy metadata. These commands are intended for use by developers within their authenticated environment and do not involve unauthorized or hidden command execution.
Audit Metadata