Trust Assessment
salesforce-sdr-admin received a trust score of 86/100, placing it in the Mostly Trusted category. This skill has passed most security checks with only minor considerations noted.
SkillShield's automated analysis identified 1 finding: 0 critical, 1 high, 0 medium, and 0 low severity. Key findings include Ability to modify Salesforce Apex/LWC/Aura code.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 13, 2026 (commit 13146e6a). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| HIGH | Ability to modify Salesforce Apex/LWC/Aura code The skill is explicitly designed to allow the AI agent to edit or create Apex, Lightning Web Components (LWC), and Aura components directly within the Salesforce Setup/Developer Console UI. This capability grants the agent the ability to execute arbitrary code within the Salesforce environment, which could be leveraged for data exfiltration, privilege escalation, or introducing backdoors if the agent is compromised or tricked. While the skill mentions 'Never run anonymous Apex that mutates data without explicit confirmation,' the ability to modify persistent code (Apex classes, triggers, LWC/Aura components) is a significant risk that requires extremely robust user confirmation and prompt injection defenses. Implement stricter, multi-factor confirmation for any code modification actions (Apex, LWC, Aura), explicitly distinguishing between read-only development tasks and code deployment/modification. Ensure that any such confirmation explicitly states the full impact of the code change. Consider restricting this capability to only trusted, pre-approved code changes or requiring human review for all deployments. Strengthen prompt injection defenses specifically for code modification instructions to prevent malicious code from being introduced. | LLM | SKILL.md:38 |
Scan History
Embed Code
[](https://skillshield.io/report/5ca65bf1ee6f9473)
Powered by SkillShield