Skip to main content

AGENTFORCE-SEC-02: Secret Written to Debug Log

๐Ÿ”ด High ยท Credential Exposure

Detects Apex System.debug calls that log access tokens, client secrets, passwords, Authorization headers or the session id. Debug logs are readable by admins and support users and are often exported, so the logged credential can be replayed.

Detailsโ€‹

FieldValue
Rule IDAGENTFORCE-SEC-02
SeverityHigh
CategoryCredential Exposure
ComplianceSOC2_CC6, PCI_DSS

Remediationโ€‹

Remove the debug statement or log a non-sensitive marker instead (e.g. token length or the last 4 characters). Keep credentials in Named Credentials / External Credentials so Apex never handles them.

See Alsoโ€‹