Review recommended
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
passThis skill facilitates running the Salesforce Code Analyzer. It includes several Node.js scripts to manage scan results, filter vendor files, and apply automated fixes. While no malicious behavior was found, the skill has an indirect prompt injection surface because it processes untrusted code and violation messages. Additionally, some scripts use shell execution with user-provided parameters, which is a potential command injection vector if the agent is misled.
Socket
warn2 alerts: gptSecurity
Snyk
passRisk: LOW · No issues