agentforce-generate

Warn

Audited by Socket on Aug 14, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/agentscript-sdk-loader.mjs

No explicit malicious payload is evident in this fragment (no networking, credential theft, or obvious dangerous primitives). However, it is a dynamic SDK/module loader: it ultimately executes code from paths derived from an environment-variable override, a cached on-disk manifest, or discovered node_modules package.json metadata. This creates a potentially high-impact supply-chain/initialization-time arbitrary code execution risk if any of those inputs or filesystem locations can be influenced or tampered with.

Confidence: 68%Severity: 70%
Audit Metadata
Analyzed At
Aug 14, 2026, 04:54 PM
Package URL
pkg:socket/skills-sh/forcedotcom%2Fsf-skills%2Fagentforce-generate%2F@21e14f935e8df04e70467893f2cc79da545acabc7c9c81ea7e2c9416811d6c92
Security Audit — socket — agentforce-generate