AGENTFORCE-SEC-02: Secret Written to Debug Log
๐ด High ยท Credential Exposure
Detects Apex System.debug calls that log access tokens, client secrets, passwords, Authorization headers or the session id. Debug logs are readable by admins and support users and are often exported, so the logged credential can be replayed.
Detailsโ
| Field | Value |
|---|---|
| Rule ID | AGENTFORCE-SEC-02 |
| Severity | High |
| Category | Credential Exposure |
| Compliance | SOC2_CC6, PCI_DSS |
Remediationโ
Remove the debug statement or log a non-sensitive marker instead (e.g. token length or the last 4 characters). Keep credentials in Named Credentials / External Credentials so Apex never handles them.