AGENTFORCE-SEC-01: Committed Credential
๐จ Critical ยท Credential Exposure
Detects credentials committed to the repository in any file: connected-app consumer keys and secrets (Custom Metadata, XML), private keys, AWS/GitHub/Slack/Stripe/Google/OpenAI tokens, Salesforce access tokens and high-entropy values assigned to secret-named keys. Placeholders, tests, fixtures, lockfiles and example files are excluded; values are redacted in the report.
Detailsโ
| Field | Value |
|---|---|
| Rule ID | AGENTFORCE-SEC-01 |
| Severity | Critical |
| Category | Credential Exposure |
| Compliance | SOC2_CC6, PCI_DSS |
Remediationโ
Rotate the credential first (it is in git history even after deletion), then remove it from the repository and load it at runtime: Named Credentials / External Credentials or protected Custom Metadata populated per org for Salesforce, environment variables or a secret manager elsewhere. Add the path to secret scanning in CI.