Back to skill

Security audit

SF Business Data Export

Security checks for vulnerabilities and agentic risk

Overview

This Salesforce export skill is mostly coherent, but it needs review because it handles sensitive CRM data and has concrete token-disclosure and spreadsheet-safety weaknesses.

Install only in a controlled environment and use it with Salesforce accounts whose export permissions are appropriate. Before real use, confirm the exact objects, fields, time range, and output directory; use only trusted auth JSON files; treat generated Excel/CSV/JSON files as sensitive; and patch or review the exporter to validate Salesforce HTTPS hosts, block redirects/private destinations, and neutralize spreadsheet formulas.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/export_soap_to_excel.py:137
Finding

Unvalidated Salesforce Instance URL Enables SSRF and Session Token Disclosure

Content
View full analysis
ET.Element: resp = self.session.post( self.endpoint, data=body.encode('utf-8'), headers=self.headers, timeout=120 ) ``` The endpoint and credential are loaded directly from a caller-supplied JSON file: ```python auth = json.loads(Path(args.auth_json).read_text(encoding='utf-8'))['result'] client = SoapClient(auth['instanceUrl'], auth['accessToken'], auth['apiVersion']) ``` The access token is subsequently embedded in every SOAP request: ```python {self.access_token} ``` ### Technical Analysis `instanceUrl` is accepted without checking its scheme, hostname, port, or relationship to an approved Salesforce domain. The value is concatenated into a request endpoint and passed directly to `requests.Session.post()`. A crafted authentication JSON file can therefore redirect SOAP requests to an attacker-controlled server or an internal network service. Because the SOAP body contains the Salesforce session token, an attacker controlling the destination receives the token in plaintext at the HTTP application layer. The code also does not explicitly require HTTPS. A supplied `http://` URL would transmit the session token without transport encryption. The `requests` client follows redire ...[truncated 1789 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/export_soap_to_excel.py:213
Finding

Salesforce Data Is Written to Excel Without Formula-Injection Neutralization

Content
View full analysis
tuple[Path, int, list[str]]: soql_path = SOQL_DIR / f'{object_name}.soql' soql_text = soql_path.read_text(encoding='utf-8') columns = parse_select_columns(soql_text) labels = load_labels(object_name) output_path = EXPORT_DIR / f'{object_name}.xlsx' wb = Workbook(write_only=True) ws = wb.create_sheet(title=object_name[:31]) ws.append([labels.get(col, col) for col in columns]) count = 0 for record in iter_query_records(client, soql_text): flat = flatten_record(record) ws.append([flat.get(col, '') for col in columns]) count += 1 ``` The same unsafe write pattern is used by the staged detail export: ```python for record in iter_query_records(client, soql): flat = flatten_record(record) ws.append([flat.get(col, '') for col in columns]) ``` ### Technical Analysis Values retrieved from Salesforce are written directly into `.xlsx` cells through `openpyxl`. No distinction is made between ordinary text and strings beginning with spreadsheet formula markers, especially `=`. When a value beginning with `=` is assigned to an `openpyxl` cell, it can be stored as a formula rather than literal text. Consequently, an attacker who can control an exported Salesforce text field may inject a formula that executes when a business user opens the generated workbook. Depending on the spreadsheet application and its security configuration, injected formulas may: - Initiate outbound requests through external links or formula functions. - Disclose workbook content through attacker-controlled URLs. - Present deceptive links or calculated values. - Trigger legacy DDE or similar operating-system integration behavior in vulnerable or permissively con ...[truncated 1590 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (22)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a full Salesforce data export skill that accepts natural-language requests and performs record extraction, query generation, relationship handling, and Excel export. The supplied code does none of that. It only loads two local JSON files, compares expected fields against describe metadata and exported field lists, and writes a CSV catalog of field metadata and inclusion status. While this could be a supporting utility for an export workflow, the chunk’s actual primary purpose is metadata catalog generation, not Salesforce data export. Therefore the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description centers on a data-export skill that retrieves large Salesforce datasets and outputs business-readable Excel files based on natural-language requests. The supplied code chunk instead performs metadata preparation: it loads or fetches sObject describe metadata, extracts record type info, resolves page/record-type context, ingests field lists from files, and saves a JSON payload for later use. While this may be a supporting component in a larger Salesforce export workflow, the code itself does not carry out the declared primary purpose and lacks the key advertised behaviors (data extraction, SOQL generation, Excel export, relationship traversal, SOAP/queryMore handling, etc.). Therefore the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The code is related to one narrow subpart of the description: it derives fields from layouts/flexipages and generates SOQL templates, including some support for polymorphic Owner handling and a two-step query note for order details. However, the declared purpose describes a much broader skill centered on fulfilling natural-language export requests and producing business-readable Excel exports from Salesforce data, including actual data extraction through SOAP/queryMore. This script does not connect to Salesforce, execute queries, fetch data, or generate Excel outputs. Its primary purpose is metadata analysis and static SOQL/template generation for a predefined object set. That is a material mismatch in primary behavior and capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is about exporting Salesforce business data into Excel from natural-language requests and handling Salesforce querying/export logic. The supplied code does not perform any data export, natural-language interpretation, SOQL generation, relationship traversal, SOAP querying, or Excel creation. Instead, it performs setup validation for the runtime environment and Salesforce authentication. While these checks may support the broader export skill, this specific code chunk's primary purpose is materially different from the declared behavior, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description is centered on a Salesforce export skill: interpreting natural-language requests, generating object-level SOQL, traversing relationships, and exporting large datasets into business-readable Excel files. The supplied code does none of that. Instead, it is a standalone post-processing validation utility that reads a JSON array of per-object metrics, checks thresholds and count consistency, and emits a JSON report. This is a materially different primary purpose, not just an implementation detail of export. No undeclared dangerous capability is present, but the code's behavior does not accurately represent the declared export functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description centers on a Salesforce export skill with substantial data-retrieval and transformation capabilities. The supplied code chunk instead only converts a JSON manifest into a CSV file with predetermined review fields. This is not a supporting implementation detail for the claimed behavior; it is a materially different and much narrower utility focused on manifest normalization. No Salesforce APIs, query construction, business-readable export formatting, or Excel-specific processing are present.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 362)May include surrounding context.

md
Keep `SKILL.md` focused on decision-making and workflow. Move object-specific mappings and reusable implementation details into scripts or references.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill describes and depends on powerful capabilities including filesystem access, shell execution, and network/Salesforce connectivity, but it does not declare any explicit tool scope or permission boundaries. In an agent environment, this creates unnecessary privilege ambiguity and increases the chance that the skill can read, write, or transmit sensitive data beyond what a user reasonably expects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is explicitly designed to export Salesforce business data into local files, including review-ready spreadsheets and manifests, yet it does not require any warning, consent checkpoint, or safe-handling guidance for potentially sensitive data. This increases the risk of accidental mass extraction, local persistence of confidential records, and onward sharing of data outside governed Salesforce controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction 'Prefer Chinese labels for the final Excel header row when labels are available' imposes a language preference by default. Because the skill only lists language preference as an optional input and does not require explicit user choice before applying Chinese output, this can violate language/locale policies.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This line repeats a locale-specific default by instructing the skill to use user-language labels when available while preferring Chinese labels when available. Defaulting to a specific language without opt-in is a natural-language policy concern unless the skill is clearly documented as region-specific, which this file does not do.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction 'use Chinese labels for the header row when labels are available' imposes a specific language requirement in the output specification. This is a natural-language locale policy concern because the file does not offer user opt-in, alternatives, or a documented region-specific justification.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/owner-polymorphism.md (reported line 68)May include surrounding context.

md
- `Quote`
- custom objects whose owner can be queue or user

Do not generalize from one object to another without checking `describe`.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The guidance explicitly recommends including parent owner and business context fields in review exports, which can expose personal and sensitive business metadata beyond the minimum data needed for the task. In this skill's context—large-scale Salesforce data export to Excel for business users—normalizing broad inclusion of owner names, sales teams, and sales groups increases the risk of overbroad disclosure, internal data leakage, and unauthorized redistribution in offline files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code writes queried CRM records into .xlsx files and later creates a CSV manifest, but there is no confirmation prompt, warning comment, or docstring disclosing that potentially sensitive customer/business data will be persisted locally. Although a per-object status line is printed after completion, it does not warn the user beforehand about the data export side effect.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest describes exporting Salesforce business data from natural-language requests, including two-step detail queries, which implies the generated export should reflect the requested dataset. In the special-case order-details path, the code silently injects a fixed LastModifiedDate < 2026-03-22T16:00:00Z filter, so this export behavior is narrower and materially different from a normal object-level export without any indication in the interface or documentation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The script loads an access token from an auth JSON file and uses it to make HTTP SOAP requests to the Salesforce instance, but there is no user-facing warning or explanatory comment about credential handling or network transmission. For a script that accesses external services with sensitive tokens, some explicit disclosure is expected unless the behavior is clearly documented elsewhere in the skill materials.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The generated summary content is hard-coded in Chinese, which imposes a specific language on users without any opt-in or locale selection. The policy allows locale constraints only when the user is given a choice or the restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/collect_metadata.py (reported line 36)May include surrounding context.

python
def run_command(args: list[str]) -> tuple[bool, str]:
    try:
        completed = subprocess.run(
            args,
            check=False,
            capture_output=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/preflight_check.py (reported line 17)May include surrounding context.

python
def run_command(args: list[str]) -> tuple[bool, str]:
    try:
        completed = subprocess.run(
            args,
            check=False,
            capture_output=True,

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This manifest-like JSON defines all user-facing field labels in Chinese only, such as '机会 ID' and '关闭日期'. Because the file provides no indication of user opt-in, alternate locale support, or region-specific justification, it appears to impose a specific language in a way that can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code creates and overwrites CSV, SOQL, and Markdown files under the analysis and soql directories via write operations, but there is no confirmation prompt, print/log message, or inline warning explaining that files will be generated or replaced. Because this is a code file and the behavior affects the user's filesystem, it meets the missing-disclosure criterion for file writes.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.