Back to skill

Security audit

Salesforce

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent Salesforce CLI helper, but it deserves Review because it can read, export, and modify sensitive CRM records without clear guardrails.

Install only if you are comfortable letting an agent use your Salesforce CLI session. Verify the target org before each run, prefer a sandbox or least-privilege Salesforce account, and require explicit approval before exports, imports, bulk upserts, or record-changing commands. Treat contact details, account notes, opportunity descriptions, and pipeline exports as confidential business data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description is broad enough to trigger on generic CRM, contact lookup, pipeline, and account-info requests that may not require Salesforce access. In an agent environment, this can cause over-selection of a powerful data-access skill, increasing the chance of unnecessary exposure of sensitive business records or PII when a narrower or safer skill would have sufficed.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
These sections explicitly guide lookup of contact emails, decision-makers, account details, and data export/cross-tool workflows without any privacy, least-privilege, or authorization safeguards. Because Salesforce commonly contains regulated customer and employee data, this omission can normalize bulk extraction, sharing to other tools, or outreach based on PII without verifying business need, consent, or policy compliance.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.