agentforce-generate

Warn

Audited by Socket on Sep 19, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/agentscript-sdk-loader.mjs

No explicit malicious payload is evident in this fragment (no networking, credential theft, or obvious dangerous primitives). However, it is a dynamic SDK/module loader: it ultimately executes code from paths derived from an environment-variable override, a cached on-disk manifest, or discovered node_modules package.json metadata. This creates a potentially high-impact supply-chain/initialization-time arbitrary code execution risk if any of those inputs or filesystem locations can be influenced or tampered with.

Confidence: 68%Severity: 70%
Audit Metadata
Analyzed At
Sep 19, 2026, 03:51 PM
Package URL
pkg:socket/skills-sh/forcedotcom%2Fsf-skills%2Fagentforce-generate%2F@4e8ee42624bf16cc7cdececf60d5dab3714db4ff7d2eef79de22bc5907bd09dd
Security Audit — socket — agentforce-generate