salesforce

Warn

Audited by Socket on Sep 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated Salesforce purpose matches the API operations, but the skill routes all access and bearer authentication through Maton intermediary domains instead of official Salesforce endpoints. That proxy model is explicit rather than hidden, so this is not confirmed malware, but it is a medium-high security risk due to third-party credential/data handling and added transitive trust.

Confidence: 90%Severity: 69%
Audit Metadata
Analyzed At
Sep 4, 2026, 01:52 PM
Package URL
pkg:socket/skills-sh/craftos-dev%2Fcraftbot%2Fsalesforce%2F@d9aa3e6a2b4c4dc69d7294f35787ac4833816974e8e8b702bd0de973f744407e
Security Audit — socket — salesforce