AGENTFORCE-SEC-05: Secret Stored in Public or Unprotected Custom Metadata
๐ก Medium ยท Credential Exposure
Detects Custom Metadata types designed to hold secrets (fields named like secret, password, token, API key, private key, HMAC or signing key) whose type is Public or whose records are unprotected, even when the committed value is a placeholder. This is a storage-design finding: the value is readable by any Apex in the org and by users who can view setup, travels with every deployment and sandbox copy, and is easy to commit. Committed real values are reported separately by AGENTFORCE-SEC-01.
Detailsโ
| Field | Value |
|---|---|
| Rule ID | AGENTFORCE-SEC-05 |
| Severity | Medium |
| Category | Credential Exposure |
| Compliance | SOC2_CC6, PCI_DSS |
Remediationโ
Store the secret in a Named Credential / External Credential (or a protected custom setting in a managed package) and reference it from Apex with callout:<name> or the credential APIs. Remove the field from the Custom Metadata type and rotate any value that was ever committed.