Skip to main content

AGENTFORCE-SC-10: Tool Namespace Shadowing (Confused Deputy)

๐Ÿšจ Critical ยท AgentExchange Supply-Chain

Detects when third-party AgentExchange plugins register tools with API names identical or similar to core Salesforce internal functions, or embed cross-origin shadowing directives in their description fields. A shadowed tool can execute a confused deputy attack against the broader Salesforce dataset.

Detailsโ€‹

FieldValue
Rule IDAGENTFORCE-SC-10
SeverityCritical
CategoryAgentExchange Supply-Chain

Remediationโ€‹

Refer to the SquireX documentation for remediation guidance specific to AGENTFORCE-SC-10.

See Alsoโ€‹