Skip to main content

AGENTFORCE-SEC-01: Committed Credential

๐Ÿšจ Critical ยท Credential Exposure

Detects credentials committed to the repository in any file: connected-app consumer keys and secrets (Custom Metadata, XML), private keys, AWS/GitHub/Slack/Stripe/Google/OpenAI tokens, Salesforce access tokens and high-entropy values assigned to secret-named keys. Placeholders, tests, fixtures, lockfiles and example files are excluded; values are redacted in the report.

Detailsโ€‹

FieldValue
Rule IDAGENTFORCE-SEC-01
SeverityCritical
CategoryCredential Exposure
ComplianceSOC2_CC6, PCI_DSS

Remediationโ€‹

Rotate the credential first (it is in git history even after deletion), then remove it from the repository and load it at runtime: Named Credentials / External Credentials or protected Custom Metadata populated per org for Salesforce, environment variables or a secret manager elsewhere. Add the path to secret scanning in CI.

See Alsoโ€‹