Skip to main content

AGENTFORCE-19.2: CDC Without Field Filter in Agent Context

๐Ÿ”ด High ยท Platform Event Security

Detects Change Data Capture triggers that deliver unfiltered field changes to agent contexts. CDC triggers run in system context and bypass FLS โ€” without getChangeEventHeader().getChangedFields() filtering, all changed fields (including restricted PII) are passed to the agent.

Detailsโ€‹

FieldValue
Rule IDAGENTFORCE-19.2
SeverityHigh
CategoryPlatform Event Security
ComplianceSOC2_CC7, NIST_AI_RMF

Remediationโ€‹

Refer to the SquireX documentation for remediation guidance specific to AGENTFORCE-19.2.

See Alsoโ€‹