4.37.0

    Agentforce Vibes

    Extension for developing on the Salesforce Platform with the help of generative AI

    Rank#-4581
    Publisher salesforceRegistry openvsx561,845Last scanned Sep 30, 2026, 06:10 PMRegistryHomepageGitHub
    Created
    3 years ago
    Last commit
    7 days ago
    Latest release
    v4.35.02 weeks ago

    Security Findings

    39

    Credential harvesting

    MaliciousScanner

    Hardcoded secret + sensitive file access

    Credential exfiltration chain

    MaliciousScanner

    Sensitive file access (homedir(),e.SFDX_STATE_FOLDER)}static get SF_DIR(){return b_t.join(vSr.homedir(),e.SF_STATE_FOLDER)}static get DIR(){ret...) with exfiltration URL (https://attacker.example.com/steal)

    Releaser has low repo tenure

    SuspiciousLineage

    Release author 'svc-idee-bot' has no commits in the repo older than 30d before the release

    Suspicious URL TLD2×

    SuspiciousScanner

    URL with suspicious TLD .xyz: https://api.together.xyz/v1/

    URL with suspicious TLD .xyz: https://api.ambient.xyz/v1

    Dynamic exec of remote content (VSX)

    SuspiciousScanner

    Download-and-execute in dist/skills/dx-org-devhub-configure/scripts/test-devhub.sh: chmod +x

    dist/skills/dx-org-devhub-configure/scripts/test-devhub.sh

    Hardcoded secrets/API keys28×

    SuspiciousScanner

    Secret Keyword: MASTR...****

    Secret Keyword: SENSE...****

    Secret Keyword: ABLIT...****

    Secret Keyword: NAN_A...****

    Secret Keyword: ABOVE...****

    Secret Keyword: ALIBA...****

    Secret Keyword: SARVA...****

    Secret Keyword: PERPL...****

    Secret Keyword: REGOL...****

    Secret Keyword: GMICL...****

    Secret Keyword: ZHIPU...****

    Secret Keyword: DINFE...****

    Secret Keyword: NEON_...****

    Secret Keyword: OPPER...****

    Secret Keyword: Autho...****

    Secret Keyword: INCEP...****

    Secret Keyword: MISTR...****

    Secret Keyword: HELIC...****

    Secret Keyword: AIXY_...****

    Secret Keyword: AWS_S...****

    Secret Keyword: https...****

    Secret Keyword: _STRI...****

    Secret Keyword: anthr...****

    Secret Keyword: funct...****

    Secret Keyword: opena...****

    Secret Keyword: ANTHR...****

    Secret Keyword: strin...****

    Secret Keyword: numbe...****

    dist/extension.js

    Hardcoded secrets/API keys

    SuspiciousScanner

    Basic Auth Credentials: ****

    dist/skills/automation-sandbox-post-copy-configure/references/rules_gotchas.md

    Sensitive file access3×

    SuspiciousScanner

    Access to sensitive file: /etc/passwd

    Access to sensitive file: ~/.ssh

    Access to sensitive file: homedir(),e.SFDX_STATE_FOLDER)}static get SF_DIR(){return Aor.join(rNn.homedir(),e.SF_STATE_FOLDER)}static get DIR(){ret...

    Coverage evasion (executable content over cap)

    SuspiciousScanner

    2435 executable file(s) totalling 34168590 bytes exceeded the bundle or per-file ceiling and were dropped or head-truncated (50.82% of code-bearing bytes reached the rules)