salesforce-flow

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose and capabilities generally align with Salesforce Flow generation, and there is no installer, credential harvesting, or obvious malware behavior. However, its core functionality depends on an undocumented MCP pipeline with unclear provenance, and it sends user/local project metadata to that service while forcing autonomous repeated execution without confirmation. Risk is moderate due to unverifiable service trust and opaque data handling, not confirmed malicious intent.

Confidence: 84%Severity: 57%
Audit Metadata
Analyzed At
Mar 16, 2026, 03:14 AM
Package URL
pkg:socket/skills-sh/forcedotcom%2Fafv-library%2Fsalesforce-flow%2F@cd9abed0a6949476098766e28fc03ecc35a8030f