agentforce-test

Warn

Audited by Socket on Aug 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS from a security-risk perspective, but not malicious. The skill is internally consistent with its stated purpose as an Agentforce testing and security-assessment skill, and its external tooling/data flows are mostly first-party Salesforce paths. The main risk comes from granting an AI agent offensive security testing capabilities, Bash execution, token-backed API calls, and the ability to trigger real org actions; these are partially mitigated by explicit confirmation and sandbox-only guidance.

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
Aug 18, 2026, 07:45 PM
Package URL
pkg:socket/skills-sh/forcedotcom%2Fsf-skills%2Fagentforce-test%2F@ee2e79683c65b060ef58e6cac4bfe375ea1b368e6bcfb35615f61cac888c9cb2
Security Audit — socket — agentforce-test