sf-datacloud-act
Warn
Audited by Socket on Mar 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's capabilities mostly fit its stated Salesforce Data Cloud activation purpose, and its data flow appears directed through normal Salesforce CLI usage. However, it depends on an unverified community `sf data360` plugin and a local bundled script, creating a meaningful supply-chain trust issue for an agent that can mutate real downstream delivery configurations.
Confidence: 87%Severity: 78%
Audit Metadata