sf-datacloud-act

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's capabilities mostly fit its stated Salesforce Data Cloud activation purpose, and its data flow appears directed through normal Salesforce CLI usage. However, it depends on an unverified community `sf data360` plugin and a local bundled script, creating a meaningful supply-chain trust issue for an agent that can mutate real downstream delivery configurations.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
Mar 21, 2026, 09:13 PM
Package URL
pkg:socket/skills-sh/Jaganpro%2Fsf-skills%2Fsf-datacloud-act%2F@26e9dc1816d5878ebda325d9944ff6e25a75c94d