Scanned skills

forcedotcom/sf-skills agentforce-d360-analyze

Checked the catalogued skill at agentforce-d360-analyze.

SkillTrust corpus scan 19 September 2026 v0.10.0 via skillsh Verify on GitHub
F AI-triaged 45
D Security

D; retained sample includes a high finding · SD-022 · what this rule accepts as a false positive →

F Permissions

F; retained sample includes a critical finding · SD-004 · what this rule accepts as a false positive →

A Transparency

A set by no findings on this axis

showing 10 of 45
securityhigh SD-022
SKILL.md
permission_hygienehigh SD-003
scripts/assemble_dc.py
permission_hygienecritical SD-004
scripts/assemble_dc.py
securityhigh SD-007
scripts/dc.py
securityhigh SD-007
scripts/dc.py
securityhigh SD-007
scripts/dc.py
permission_hygienehigh SD-003
scripts/discover_sessions.py
permission_hygienehigh SD-003
scripts/discover_sessions.py
permission_hygienehigh SD-003
scripts/discover_sessions.py
securityhigh SD-007
scripts/tests/fixtures/synthetic_session.py
2 suppressed by AI triage
permission_hygienehigh SD-003 benign_example
scripts/_shared/paths.py

The code merely documents that path traversal is detected and prevented, not that it is allowed.

permission_hygienehigh SD-003 benign_example
scripts/storage.py

The code intentionally writes a relative path to link session files outside the skill directory as part of normal operation.