agentforce-generate

Warn

Audited by Socket on Aug 18, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/agentscript-sdk-loader.mjs

No explicit malicious payload is evident in this fragment (no networking, credential theft, or obvious dangerous primitives). However, it is a dynamic SDK/module loader: it ultimately executes code from paths derived from an environment-variable override, a cached on-disk manifest, or discovered node_modules package.json metadata. This creates a potentially high-impact supply-chain/initialization-time arbitrary code execution risk if any of those inputs or filesystem locations can be influenced or tampered with.

Confidence: 68%Severity: 70%
Audit Metadata
Analyzed At
Aug 18, 2026, 07:44 PM
Package URL
pkg:socket/skills-sh/forcedotcom%2Fsf-skills%2Fagentforce-generate%2F@505b846fef6eb05dc82780a826dd8b8d9f3104dcd38c151dfc48f304cf84e6f3
Security Audit — socket — agentforce-generate