Salesforce SDR Admin (Browser)

Security checks across malware telemetry and agentic risk

Overview

This Salesforce browser-assistant skill has powerful admin capabilities, but they are disclosed, purpose-aligned, and gated by user confirmation.

Install only if you want an agent to operate Salesforce through your browser. Use a least-privileged Salesforce account, prefer sandbox for risky admin or development changes, protect local credential files and browser profiles, and carefully review every create, update, delete, setup, or deployment action before confirming.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The file documents a record deletion workflow with only mechanical steps and no warning about destructive impact, reversibility, required authorization, or confirmation standards beyond the UI dialog. In a browser-automation skill for Salesforce administration, this omission can normalize unsafe deletion actions and make accidental or overly broad destructive operations more likely.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal