Salesforce SDR Admin (Browser)

ReviewAudited by ClawScan on May 10, 2026.

Overview

This instruction-only skill is coherent for Salesforce browser admin work, but it relies on local Salesforce credentials and can change CRM/admin data after user confirmation.

Install only if you want an agent to operate Salesforce in your browser. Use a least-privileged Salesforce account, attach only the intended Salesforce tab/profile, keep local credential files protected, never paste secrets into chat, and review all proposed changes before confirming.

Findings (2)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

If confirmed, the agent could change or delete business records, alter Salesforce setup, or make development changes in a Salesforce org.

Why it was flagged

The skill is designed to perform high-impact Salesforce UI actions, including record changes, setup changes, and deployments. The confirmation requirement makes this purpose-aligned, but the user should recognize the authority being granted.

Skill content
Always confirm before any write action (create/update/delete, setup changes, deployments).
Recommendation

Use least-privileged Salesforce accounts, prefer sandbox environments for risky changes, and carefully review every dry-run summary before approving writes.

What this means

The agent may act with the permissions of the Salesforce account available in local credentials or the attached browser session.

Why it was flagged

The skill expects access to Salesforce login material from local stores or the browser profile. This is aligned with Salesforce browser automation and includes guidance not to paste secrets into chat, but it is still sensitive account access.

Skill content
Allowed Sources: 1. Environment variables ... 2. Local credential file ... 3. Browser autofill in the attached Chrome profile
Recommendation

Use a dedicated, least-privileged Salesforce user or profile where possible, protect the local credential file, and avoid attaching browser profiles that contain unrelated sensitive sessions.