sf-connected-apps

Warn

Audited by Runlayer on Mar 15, 2026

Risk Level: MEDIUM
Scan Summary
Max Score
89%
Files
18
Flagged
10
Chunks
19
Flagged Files (10)
sf-connected-apps/references/oauth-flows-reference.mdMEDIUM
89.3%

Tool passed security scan

Malicious tool definition detected

sf-connected-apps/assets/eca-oauth-settings.xmlMEDIUM
76.8%

Malicious tool definition detected

- RefreshToken: Offline access via refresh token - OpenID: OpenID Connect (user identity) - Profile: User profile information - Email: User email address - Web: Web browser access - ChatterApi: Chatter REST API - CustomPermissions: Custom permission access IMPORTANT: OAuth flows (Authorization Code, Client Credentials, etc.) are configured via the Admin UI or ExtlClntAppOauthConfigurablePolicies, NOT here.

sf-connected-apps/SKILL.mdLOW
71.7%

Risky tool definition detected

sf-connected-apps/assets/eca-global-oauth.xmlLOW
71.3%

Malicious tool definition detected

Tool: sf-connected-apps/assets/eca-global-oauth.xml Description: <?xml version="1.0" encoding="UTF-8"?> <!-- Template: External Client App - Global OAuth Settings Use Case: Configure OAuth settings that apply globally to the ECA Replace placeholders: - {{APP_NAME}}: The ExternalClientApplication API name (must match .eca file) - {{LABEL}}: Display label for this global OAuth settings configuration - {{CALLBACK_URL}}: OAuth callback URL (must be HTTPS for web, custom scheme for mobile) - {{PKCE_R

sf-connected-apps/.claude/hooks.yamlLOW
70.6%

Malicious tool definition detected

sf-connected-apps/assets/eca-policies.xmlLOW
69.2%

Tool passed security scan

sf-connected-apps/references/migration-guide.mdLOW
63.0%

Tool passed security scan

sf-connected-apps/assets/connected-app-jwt.xmlLOW
62.7%

Tool passed security scan

sf-connected-apps/references/example-usage.mdLOW
61.2%

Tool passed security scan

sf-connected-apps/CREDITS.mdLOW
52.5%

Tool passed security scan

Passed Files (8)Click to expand
sf-connected-apps/assets/external-client-app.xmlOK
41.6%

Tool passed security scan

sf-connected-apps/references/security-checklist.mdOK
37.0%

Tool passed security scan

sf-connected-apps/assets/connected-app-basic.xmlOK
36.4%

Tool passed security scan

sf-connected-apps/assets/connected-app-oauth.xmlOK
34.1%

Tool passed security scan

sf-connected-apps/assets/connected-app-canvas.xmlOK
31.9%

Tool passed security scan

sf-connected-apps/README.mdOK
28.2%

Tool passed security scan

sf-connected-apps/LICENSEOK
18.1%

Tool passed security scan

sf-connected-apps/references/testing-validation-guide.mdOK
9.6%

Tool passed security scan

Audit Metadata
Max File Score
89%
Classification
KNOWN_SERVER_PARTIAL_KNOWN
Files Scanned
18
Files Flagged
10
Chunks Analyzed
19
Analyzed
Mar 15, 2026, 05:33 PM
Security Audit — runlayer — sf-connected-apps