Salesforce Plugin
Security checks across malware telemetry and agentic risk
Overview
The bundle is a documentation/skill-wrapper for Salesforce-focused agent skills and its declared files and instructions align with that purpose; it contains no installers or undeclared credential requirements, though it assumes Salesforce tooling and org credentials will be available at runtime.
This bundle is a documentation and routing wrapper for Salesforce skills and appears coherent with that purpose. Before installing or invoking it: - Be prepared to provide Salesforce org access (org alias, ECA/JWT, or connected-app credentials) when you run tests or runtime APIs — the skill expects those at runtime but does not declare env vars in the manifest. - The SKILL.md instructs use of sf CLI and Python scripts; ensure you trust the repo maintainer before running any scripts locally and inspect scripts in the repository if you plan to execute them. - Do not paste long-lived secrets into chat; prefer scoped connected-app credentials and short-lived tokens where possible. - If you enable autonomous invocation for the agent, consider limiting what it can do (or grant it a non-privileged test org) because agent workflows may run commands that act against Salesforce orgs. Overall this bundle looks internally consistent and intended for Salesforce platform work; treat it like other integration skills that require platform credentials and local tooling and follow usual operational precautions.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
No VirusTotal findings
