SquireX Security Rule Catalog
112 rules across 72 categories.
Action Configurationโ
| Rule ID | Severity | Name |
|---|
AGENTFORCE-1.2 | ๐ด High | Schema Synchronization Verification |
Agent Flow Integrityโ
Agent Script Safetyโ
AgentExchange Supply-Chainโ
Agentforce for Commerceโ
| Rule ID | Severity | Name |
|---|
AGENTFORCE-17.1 | ๐จ Critical | Commerce Agent Without Idempotency Key |
AGENTFORCE-17.2 | ๐จ Critical | Commerce Agent Amount Without Bounds Check |
Agentic Architectureโ
Autonomous Schedulingโ
Custom Permission Enforcementโ
| Rule ID | Severity | Name |
|---|
AGENTFORCE-16.1 | ๐ด High | Agent Action Without Custom Permission Gate |
Data Cloud Groundingโ
| Rule ID | Severity | Name |
|---|
AGENTFORCE-13.1 | ๐จ Critical | RAG Knowledge Source Without Schema Classification |
Data Exfiltrationโ
| Rule ID | Severity | Name |
|---|
AGENTFORCE-21.1 | ๐จ Critical | PII/PHI Payload Leakage in Tool Output |
Data Exfiltration / Injectionโ
| Rule ID | Severity | Name |
|---|
AGENTFORCE-21.2 | ๐ด High | Insecure Output Handling (Agent-to-XSS) |
Einstein Copilot Studio Configurationโ
| Rule ID | Severity | Name |
|---|
AGENTFORCE-12.2 | ๐จ Critical | GenAiPlannerBundle API Version Drift |
AGENTFORCE-12.1 | ๐จ Critical | Latent Memory Poisoning in Prompt Template |
Excessive Agencyโ
| Rule ID | Severity | Name |
|---|
AGENTFORCE-1.1 | ๐จ Critical | Mandatory User Confirmation |
AGENTFORCE-20.1 | ๐จ Critical | DML Bypassing FLS in Invocable Actions |
AGENTFORCE-20.2 | ๐จ Critical | Unconstrained ModifyAllData in Agent Context |
SNOW-20.2 | ๐จ Critical | Role Masking Not Configured for Dynamic User Agent |
External Service Securityโ
| Rule ID | Severity | Name |
|---|
AGENTFORCE-15.2 | ๐ด High | Dynamic Cloaking via External RAG Source |
AGENTFORCE-15.1 | ๐ด High | External Service Without Certificate Pinning |
Governanceโ
| Rule ID | Severity | Name |
|---|
AGENTFORCE-4.3 | ๐ด High | Synthetic Evaluation Completeness |
Graph: Cascading Automationโ
| Rule ID | Severity | Name |
|---|
AGENTFORCE-32.1 | ๐ด High | Unintended Autonomous Blast Radius |
Graph: Component Injectionโ
| Rule ID | Severity | Name |
|---|
AGENTFORCE-34.1 | ๐จ Critical | Agent-to-UI XSS (Component Injection Graph) |
Graph: MCP Identity Mismatchโ
Graph: PII Exfiltration Pathโ
| Rule ID | Severity | Name |
|---|
AGENTFORCE-30.1 | ๐จ Critical | Context Window PII Poisoning (Graph) |
Graph: Privilege Escalation Pathโ
| Rule ID | Severity | Name |
|---|
AGENTFORCE-31.1 | ๐จ Critical | Autonomous Without-Sharing Escalation (Deep) |
Grounding Securityโ
| Rule ID | Severity | Name |
|---|
AGENTFORCE-3.1 | ๐จ Critical | Hardcoded Sensitive Indicators |
AGENTFORCE-3.2 | ๐จ Critical | Field-Level Security Masking Alignment |
Headless MCP Accessโ
Injectionโ
Instruction Integrityโ
MCP Authenticationโ
| Rule ID | Severity | Name |
|---|
AGENTFORCE-24.2 | ๐ด High | Missing Signature Validation on Agent Webhook |
MuleSoft Agent Fabricโ
Multi-Agent Orchestrationโ
| Rule ID | Severity | Name |
|---|
AGENTFORCE-18.1 | ๐จ Critical | Compositional Fragment Trap Risk |
AGENTFORCE-18.2 | ๐ด High | Sybil Identity in Multi-Agent Orchestration |
SNOW-18.2 | ๐ด High | Yokohama Agent Duplication Sybil |
Network Securityโ
OpenGraph Securityโ
Operational Reliabilityโ
Orchestration Integrityโ
| Rule ID | Severity | Name |
|---|
AGENTFORCE-4.1 | ๐ด High | Planner Orchestration Completeness |
Privilege Escalationโ
Prompt Injectionโ
Resource Exhaustionโ
| Rule ID | Severity | Name |
|---|
AGENTFORCE-23.1 | ๐ด High | Non-Selective SOQL in Agent Tools (Agent DoS) |
Runtime Capability Driftโ
| Rule ID | Severity | Name |
|---|
AGENTFORCE-22.1 | ๐จ Critical | Unsafe Autonomous HTTP Callouts |
Security Configurationโ
| Rule ID | Severity | Name |
|---|
AGENTFORCE-PT-02 | ๐ด High | Experimental Template Activation Exposure |
ServiceNow ACLโ
| Rule ID | Severity | Name |
|---|
SNOW-28.1 | ๐จ Critical | ACL Script Using GlideRecord (Recursive Bypass) |
SNOW-28.6 | ๐ด High | addEncodedQuery Without User Context Restriction |
ServiceNow API Authenticationโ
| Rule ID | Severity | Name |
|---|
SNOW-24.1 | ๐ด High | Agent API Endpoint Without OAuth Scope Validation |
ServiceNow Agent Architectureโ
| Rule ID | Severity | Name |
|---|
SNOW-7.1 | ๐ก Medium | Agent Instruction Bloat |
ServiceNow Autonomous Schedulingโ
| Rule ID | Severity | Name |
|---|
SNOW-11.1 | ๐ด High | Scheduled Job Invoking Agent Without Guardrail |
ServiceNow Data Exfiltrationโ
| Rule ID | Severity | Name |
|---|
SNOW-21.1 | ๐จ Critical | Agent Script Accessing Sensitive Table Without Privacy Guard |
ServiceNow Data Privacyโ
| Rule ID | Severity | Name |
|---|
SNOW-13.1 | ๐ด High | Agent Accessing Classified Data Without Privacy Guard |
ServiceNow Domain Separationโ
| Rule ID | Severity | Name |
|---|
SNOW-29.1 | ๐ด High | Domain Separation Drift (Missing sys_domain) |
ServiceNow Excessive Agencyโ
| Rule ID | Severity | Name |
|---|
SNOW-20.1 | ๐จ Critical | Agent Executing With Admin Privileges |
ServiceNow External Serviceโ
| Rule ID | Severity | Name |
|---|
SNOW-15.1 | ๐ด High | Integration Spoke Without Certificate Pinning |
ServiceNow Flow Securityโ
| Rule ID | Severity | Name |
|---|
SNOW-5.1 | ๐ด High | Flow Action Without Input Validation |
ServiceNow Grounding Securityโ
| Rule ID | Severity | Name |
|---|
SNOW-3.1 | ๐ด High | Grounding Source Without Classification |
ServiceNow Instruction Integrityโ
| Rule ID | Severity | Name |
|---|
SNOW-9.1 | ๐จ Critical | Prompt Injection Vector in Agent Instructions |
ServiceNow MCP Accessโ
| Rule ID | Severity | Name |
|---|
SNOW-25.1 | ๐ด High | MCP Server Without Scope Constraints |
ServiceNow MID Server Trustโ
| Rule ID | Severity | Name |
|---|
SNOW-31.1 | ๐จ Critical | MID Server / Discovery Trust Violation |
ServiceNow Memory Safetyโ
| Rule ID | Severity | Name |
|---|
SNOW-12.2 | ๐จ Critical | Latent Memory Poisoning in Agent Memory |
ServiceNow Multi-Agentโ
| Rule ID | Severity | Name |
|---|
SNOW-18.1 | ๐ด High | Multi-Agent Compositional Fragment Trap |
ServiceNow Operational Reliabilityโ
| Rule ID | Severity | Name |
|---|
SNOW-10.1 | ๐ด High | Agent DML Without Data Policy Guard |
ServiceNow Resource Exhaustionโ
| Rule ID | Severity | Name |
|---|
SNOW-23.1 | ๐ด High | Unbounded GlideRecord Query in Agent Script |
ServiceNow Role-Based Accessโ
| Rule ID | Severity | Name |
|---|
SNOW-16.1 | ๐ด High | Agent Action Without Role Gate |
ServiceNow Runtime Driftโ
| Rule ID | Severity | Name |
|---|
SNOW-27.1 | ๐จ Critical | Now Assist API Confirmation Bypass |
ServiceNow SSRFโ
| Rule ID | Severity | Name |
|---|
SNOW-22.1 | ๐จ Critical | SSRF via Dynamic RESTMessageV2 Endpoint |
ServiceNow Scope Hygieneโ
| Rule ID | Severity | Name |
|---|
SNOW-30.1 | ๐ด High | Application Scope Hygiene Violation |
ServiceNow Script Safetyโ
| Rule ID | Severity | Name |
|---|
SNOW-2.1 | ๐จ Critical | Unsafe Script Pattern in Agent Tool |
ServiceNow Skill Kitโ
| Rule ID | Severity | Name |
|---|
SNOW-12.1 | ๐ด High | Skill Kit Version Drift |
ServiceNow Structural Dependencyโ
| Rule ID | Severity | Name |
|---|
SNOW-4.1 | ๐ด High | Orphaned Agent Tool Reference |
ServiceNow Supply Chainโ
| Rule ID | Severity | Name |
|---|
SNOW-6.1 | ๐ด High | Update Set Missing Agent Dependencies |
SNOW-26.1 | ๐ด High | Skill Namespace Shadowing |
| Rule ID | Severity | Name |
|---|
SNOW-1.1 | ๐จ Critical | Agent Tool Without Confirmation Gate |
ServiceNow Trigger Executionโ
| Rule ID | Severity | Name |
|---|
SNOW-19.1 | ๐ด High | Business Rule Triggering Agent Execution |
ServiceNow Virtual Agentโ
| Rule ID | Severity | Name |
|---|
SNOW-14.1 | ๐ด High | Virtual Agent Topic Without Input Sanitization |
Slack Integration Securityโ
| Rule ID | Severity | Name |
|---|
AGENTFORCE-14.1 | ๐ด High | Slack Channel Bot Without DLP Guard |
Structural Dependencyโ
| Rule ID | Severity | Name |
|---|
AGENTFORCE-4.2 | ๐ด High | Component Deactivation Collision |
Supply Chain Securityโ
Supply Chain: ToxicSkillsโ
Unauthorized Actionโ