Skip to main content

AGENTFORCE-SEC-05: Secret Stored in Public or Unprotected Custom Metadata

๐ŸŸก Medium ยท Credential Exposure

Detects Custom Metadata types designed to hold secrets (fields named like secret, password, token, API key, private key, HMAC or signing key) whose type is Public or whose records are unprotected, even when the committed value is a placeholder. This is a storage-design finding: the value is readable by any Apex in the org and by users who can view setup, travels with every deployment and sandbox copy, and is easy to commit. Committed real values are reported separately by AGENTFORCE-SEC-01.

Detailsโ€‹

FieldValue
Rule IDAGENTFORCE-SEC-05
SeverityMedium
CategoryCredential Exposure
ComplianceSOC2_CC6, PCI_DSS

Remediationโ€‹

Store the secret in a Named Credential / External Credential (or a protected custom setting in a managed package) and reference it from Apex with callout:<name> or the credential APIs. Remove the field from the Custom Metadata type and rotate any value that was ever committed.

See Alsoโ€‹