agentforce-test
Warn
Audited by Socket on Aug 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS from a security-risk perspective, but not malicious. The skill is internally consistent with its stated purpose as an Agentforce testing and security-assessment skill, and its external tooling/data flows are mostly first-party Salesforce paths. The main risk comes from granting an AI agent offensive security testing capabilities, Bash execution, token-backed API calls, and the ability to trigger real org actions; these are partially mitigated by explicit confirmation and sandbox-only guidance.
Confidence: 89%Severity: 74%
Audit Metadata