platform-destructive-deploy

Warn

Audited by Socket on Aug 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core Salesforce destructive-deploy workflow is purpose-aligned and mostly uses official Salesforce CLI commands, but the skill depends on an unverifiable local helper script and forwards sensitive sf org display JSON into it. That hidden trust boundary is disproportionate to a documentation-style deployment skill, so overall risk is high even without clear evidence of malware or exfiltration.

Confidence: 82%Severity: 72%
Audit Metadata
Analyzed At
Aug 5, 2026, 07:09 AM
Package URL
pkg:socket/skills-sh/forcedotcom%2Fafv-library%2Fplatform-destructive-deploy%2F@2472eee2d4862465d9116c36e59ef00a3675bac449402dd0020f4ec8f16362ed
Security Audit — socket — platform-destructive-deploy