Agentforce Vibes
Extension for developing on the Salesforce Platform with the help of generative AI
- Created
- 3 years ago
- Last commit
- 7 days ago
- Latest release
- v4.35.02 weeks ago
Security Findings
39Credential exfiltration chain
MaliciousScannerSensitive file access (homedir(),e.SFDX_STATE_FOLDER)}static get SF_DIR(){return b_t.join(vSr.homedir(),e.SF_STATE_FOLDER)}static get DIR(){ret...) with exfiltration URL (https://attacker.example.com/steal)
Releaser has low repo tenure
SuspiciousLineageRelease author 'svc-idee-bot' has no commits in the repo older than 30d before the release
Suspicious URL TLD2×
SuspiciousScannerURL with suspicious TLD .xyz: https://api.together.xyz/v1/
URL with suspicious TLD .xyz: https://api.ambient.xyz/v1
Dynamic exec of remote content (VSX)
SuspiciousScannerDownload-and-execute in dist/skills/dx-org-devhub-configure/scripts/test-devhub.sh: chmod +x
dist/skills/dx-org-devhub-configure/scripts/test-devhub.sh
Hardcoded secrets/API keys28×
SuspiciousScannerSecret Keyword: MASTR...****
Secret Keyword: SENSE...****
Secret Keyword: ABLIT...****
Secret Keyword: NAN_A...****
Secret Keyword: ABOVE...****
Secret Keyword: ALIBA...****
Secret Keyword: SARVA...****
Secret Keyword: PERPL...****
Secret Keyword: REGOL...****
Secret Keyword: GMICL...****
Secret Keyword: ZHIPU...****
Secret Keyword: DINFE...****
Secret Keyword: NEON_...****
Secret Keyword: OPPER...****
Secret Keyword: Autho...****
Secret Keyword: INCEP...****
Secret Keyword: MISTR...****
Secret Keyword: HELIC...****
Secret Keyword: AIXY_...****
Secret Keyword: AWS_S...****
Secret Keyword: https...****
Secret Keyword: _STRI...****
Secret Keyword: anthr...****
Secret Keyword: funct...****
Secret Keyword: opena...****
Secret Keyword: ANTHR...****
Secret Keyword: strin...****
Secret Keyword: numbe...****
dist/extension.js
Hardcoded secrets/API keys
SuspiciousScannerBasic Auth Credentials: ****
dist/skills/automation-sandbox-post-copy-configure/references/rules_gotchas.md
Sensitive file access3×
SuspiciousScannerAccess to sensitive file: /etc/passwd
Access to sensitive file: ~/.ssh
Access to sensitive file: homedir(),e.SFDX_STATE_FOLDER)}static get SF_DIR(){return Aor.join(rNn.homedir(),e.SF_STATE_FOLDER)}static get DIR(){ret...
Coverage evasion (executable content over cap)
SuspiciousScanner2435 executable file(s) totalling 34168590 bytes exceeded the bundle or per-file ceiling and were dropped or head-truncated (50.82% of code-bearing bytes reached the rules)