sf-connected-apps
Audited by Runlayer on Mar 15, 2026
Tool passed security scan
Malicious tool definition detected
Malicious tool definition detected
- RefreshToken: Offline access via refresh token - OpenID: OpenID Connect (user identity) - Profile: User profile information - Email: User email address - Web: Web browser access - ChatterApi: Chatter REST API - CustomPermissions: Custom permission access IMPORTANT: OAuth flows (Authorization Code, Client Credentials, etc.) are configured via the Admin UI or ExtlClntAppOauthConfigurablePolicies, NOT here.
Risky tool definition detected
Malicious tool definition detected
Tool: sf-connected-apps/assets/eca-global-oauth.xml Description: <?xml version="1.0" encoding="UTF-8"?> <!-- Template: External Client App - Global OAuth Settings Use Case: Configure OAuth settings that apply globally to the ECA Replace placeholders: - {{APP_NAME}}: The ExternalClientApplication API name (must match .eca file) - {{LABEL}}: Display label for this global OAuth settings configuration - {{CALLBACK_URL}}: OAuth callback URL (must be HTTPS for web, custom scheme for mobile) - {{PKCE_R
Malicious tool definition detected
Tool passed security scan
Tool passed security scan
Tool passed security scan
Tool passed security scan
Tool passed security scan
Passed Files (8)Click to expand
Tool passed security scan
Tool passed security scan
Tool passed security scan
Tool passed security scan
Tool passed security scan
Tool passed security scan
Tool passed security scan
Tool passed security scan