salesforce-prod-checklist

Pass

Audited by Gen Agent Trust Hub on Mar 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: No security issues were identified. The skill promotes robust security practices such as using restricted OAuth scopes, dedicated service accounts, and external secrets management instead of environment variables.\n- [COMMAND_EXECUTION]: Utilizes the official Salesforce CLI (sf) for deployment and monitoring tasks. The skill's execution environment is correctly limited via the allowed-tools configuration to a specific set of necessary commands, following the principle of least privilege.\n- [EXTERNAL_DOWNLOADS]: Fetches system health information from the official Salesforce Status API (api.status.salesforce.com), which is a well-known and trusted service. This is a standard operational check during production deployments.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 25, 2026, 04:42 PM