platform-destructive-deploy
Warn
Audited by Socket on Aug 5, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core Salesforce destructive-deploy workflow is purpose-aligned and mostly uses official Salesforce CLI commands, but the skill depends on an unverifiable local helper script and forwards sensitive sf org display JSON into it. That hidden trust boundary is disproportionate to a documentation-style deployment skill, so overall risk is high even without clear evidence of malware or exfiltration.
Confidence: 82%Severity: 72%
Audit Metadata