Back to skill

Security audit

Salesforce

Security checks for vulnerabilities and agentic risk

Overview

This Salesforce skill has a legitimate purpose, but it can read, export, and change sensitive CRM data without enough scoping or user-control guidance.

Install only if you are comfortable letting the agent use your Salesforce CLI session for CRM queries and record changes. Use least-privilege Salesforce access, review commands before running exports or writes, limit selected fields and result sizes, avoid unnecessary contact-data extraction, and do not run the schema-export script with untrusted object names or in directories where file clobbering would matter.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/schema-export.sh:8
Finding

Unvalidated Output Path Enables Path Traversal and Symlink-Based File Clobbering

Content
View full analysis
[org-alias]}" ORG="${2:-}" ORG_FLAG="" if [ -n "$ORG" ]; then ORG_FLAG="--target-org $ORG" fi OUTPUT_FILE="${OBJECT}_schema.md" echo "# $OBJECT Schema" > "$OUTPUT_FILE" echo "" >> "$OUTPUT_FILE" echo "Generated: $(date)" >> "$OUTPUT_FILE" echo "" >> "$OUTPUT_FILE" echo "## Fields" >> "$OUTPUT_FILE" echo "" >> "$OUTPUT_FILE" echo "| API Name | Label | Type | Required |" >> "$OUTPUT_FILE" echo "|----------|-------|------|----------|" >> "$OUTPUT_FILE" sf sobject describe --sobject "$OBJECT" $ORG_FLAG --json 2>/dev/null | \ jq -r '.result.fields[] | "| \(.name) | \(.label) | \(.type) | \(.nillable | not) |"' >> "$OUTPUT_FILE" echo "" >> "$OUTPUT_FILE" echo "## Record Types" >> "$OUTPUT_FILE" echo "" >> "$OUTPUT_FILE" sf sobject describe --sobject "$OBJECT" $ORG_FLAG --json 2>/dev/null | \ jq -r '.result.recordTypeInfos[] | "- \(.name) (\(.developerName))"' >> "$OUTPUT_FILE" 2>/dev/null || echo "- (none)" >> "$OUTPUT_FILE" ``` ### Technical Analysis The script accepts the `OBJECT` argument without validating that it is a legitimate Salesforce object identifier. It then directly incorporates that value into a filesystem path: ```bash OUTPUT_FILE="${OBJECT}_schema.md" ``` Shell redirections subsequently open this attacker-influenced path with truncation or append semantics. Directory traversal sequences such as `../` are preserved, allowing the output to escape the intended working directory. Direct traversal-based overwriting is constrained to paths representable with the appended `_schema.md` suffix. The output filename is also predictable, and the script neither rejects symbolic links nor creates the destination securely. If an attacker who can write to the execution directory c ...[truncated 2216 chars]
Remediation
View remediation
&2 exit 1 fi ``` 2. **Use a dedicated export directory.** Resolve all generated files beneath a controlled directory rather than the caller's current directory: ```bash EXPORT_DIR="${EXPORT_DIR:-./schema-exports}" mkdir -p -- "$EXPORT_DIR" OUTPUT_FILE="$EXPORT_DIR/${OBJECT}_schema.md" ``` 3. **Reject symbolic-link destinations and avoid overwriting existing files.** Create a new temporary file securely, write all content to it, and atomically rename it only after successful generation. Verify that the final destination is not a symbolic link and apply an explicit overwrite policy. 4. **Set restrictive file permissions.** Use an appropriate `umask`, such as: ```bash umask 077 ``` 5. **Write output only after successful Salesforce processing.** Capture and validate the `sf` and `jq` output before creating or replacing the destination file. This prevents invalid object names or failed API requests from leaving a truncated file. 6. **Represent optional CLI arguments with a Bash array.** Although not the primary file-clobbering flaw, this avoids word splitting and accidental injection of additional CLI options through the org alias: ```bash ORG_FLAG=() if [[ -n "$ORG" ]]; then ORG_FLAG=(--target-org "$ORG") fi sf sobject describe --sobject "$OBJECT" "${ORG_FLAG[@]}" --json ``` ]]>
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description includes very broad activation phrases such as general CRM, account info, prospect email, and executive workflow terms, which can cause the skill to trigger in contexts beyond narrowly scoped Salesforce CLI usage. Because this skill enables querying and exporting live CRM data, overbroad activation increases the chance of unnecessary access to sensitive business and contact information during unrelated requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly supports retrieving contact emails, phone numbers, account details, and exporting CRM data, but it provides no guidance on handling sensitive customer data, least-privilege access, or approval requirements for exports and outreach use cases. In a CRM context, this omission can normalize bulk extraction or disclosure of personal and commercial data without adequate safeguards.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The markdown provides a 'Full Pipeline Export' query that extracts detailed opportunity data including account names, owner names, next steps, and descriptions, but it does not include any warning about exporting potentially sensitive business data. Because this is a markdown file, omission of privacy or data-handling cautions for bulk export behavior falls under missing user warnings.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.