dx-org-manage

Warn

Audited by Socket on Aug 14, 2026

3 alerts found:

Securityx3
SecurityMEDIUM
examples/scratch-orgs/success_definition_file.json

This fragment is not executable code; it contains sensitive Salesforce authentication/authorization material (notably an access token and connected-app consumer key) in cleartext. There is no in-fragment evidence of malicious behavior, but the credential exposure risk is high if this payload is logged, bundled into artifacts/releases, or otherwise distributed. Treat the entire JSON as a secret and ensure it is not shipped with dependencies or written to persistent logs.

Confidence: 72%Severity: 78%
SecurityMEDIUM
examples/scratch-orgs/success_edition.json

No malware or suspicious behavior is observable in this fragment because it contains only static JSON data. The primary concern is credential/identifier exposure: it includes an access token and instance URL in plaintext within an artifact that could be logged or shared downstream. Treat this data as highly sensitive and ensure it is never committed, published, or included in distributable build outputs.

Confidence: 72%Severity: 85%
SecurityMEDIUM
examples/scratch-orgs/success_snapshot.json

No malicious executable logic is present in this fragment; however, it contains highly sensitive Salesforce authentication material (notably an access token) alongside instance and identity fields. The primary security concern is credential exposure in repositories, build artifacts, logs, or dependency-related bundles. Treat any occurrence of this JSON as a secret-leak incident and ensure it is never published or logged, with rotation of any exposed tokens if applicable.

Confidence: 74%Severity: 78%
Audit Metadata
Analyzed At
Aug 14, 2026, 08:40 PM
Package URL
pkg:socket/skills-sh/forcedotcom%2Fsf-skills%2Fdx-org-manage%2F@6f16c430fca4d923c2bcbbf2e110db9d3296f6f223ae885a92849aaf631998a7
Security Audit — socket — dx-org-manage