salesforce
Warn
Audited by Socket on Sep 4, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The stated Salesforce purpose matches the API operations, but the skill routes all access and bearer authentication through Maton intermediary domains instead of official Salesforce endpoints. That proxy model is explicit rather than hidden, so this is not confirmed malware, but it is a medium-high security risk due to third-party credential/data handling and added transitive trust.
Confidence: 90%Severity: 69%
Audit Metadata