salesforce-developer
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONMETADATA_POISONING
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill includes links to documentation and project guides hosted on
jeffallan.github.io. Automated scanners (URLite) flagged these URLs as malicious or blacklisted. Manual inspection suggests these are legitimate vendor documentation pages, but the alert indicates they should be accessed with caution.\n- [CREDENTIALS_UNSAFE]: The skill demonstrates how to set up Salesforce CI/CD pipelines using JWT and SFDX Auth URLs. The examples correctly use environment secrets (e.g.,secrets.SFDX_AUTH_URL) and external key files rather than hardcoding sensitive information.\n- [REMOTE_CODE_EXECUTION]: GitHub Actions and GitLab CI templates provided in the skill download the official Salesforce CLI fromdeveloper.salesforce.com. This is a standard and expected operation for setting up Salesforce development environments.\n- [COMMAND_EXECUTION]: Thedeployment-devops.mdfile contains a variety of Salesforce DX (sf) CLI commands for org authentication, source deployment, and data management. These are educational examples intended for execution by developers in a controlled project context.\n- [METADATA_POISONING]: Automated scanners flaggedSKILL.mdas potentially malicious. However, manual review found the file to be a standard skill manifest with no signs of prompt injection, hidden content, or malicious instructions.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata