Skip to content

Agentforce and MCP threat model

Review security for an Agentforce or MCP implementation with this threat model. To let an agent run a Check, use Agentforce actions.

Use this page to review identities, trust boundaries, and controls before enabling a Record Health Check Agentforce action or MCP server.

The native action remains inside Salesforce and evaluates with the configured Agentforce principal. MCP crosses four boundaries: an approved client obtains an inbound token, calls the hosted MCP server over HTTPS, the server obtains a separate Salesforce token, and a versioned Apex REST adapter evaluates with a dedicated Salesforce integration principal.

The inbound MCP credential and outbound Salesforce credential require separate scopes, storage, rotation, revocation, and audit trails. Neither credential represents the conversational user.

ThreatRequired controlVerification
Arbitrary model inputStrict schema, no unknown fields, two-operation listInvalid-schema tests
Namespace guessingExact QualifiedApiName; no alternate-name retryNamespaced tests
Record probingSalesforce sharing and user-mode access; rate limits; no denied-record disclosureAccess tests
Service identity mistaken for user delegationSetup documentation; prefer native action for in-org useIdentity review
Prompt injection in stored textTreat output as data; exclude display text; fixed agent instructionsInjection suite
Tool side effectsRead-only operations; publication NONE; no generic Apex or SOQLMutation and event tests
Diagnostics disclosureAllow only four bounded, disclosure-safe diagnosis fields; exclude raw administrator diagnostics; integration user lacks diagnostics permissionContract and restricted-user tests
Credential theftManaged secrets, narrow scopes, rotation, token validation, no token logsRotation and log tests
Server-side request forgerySalesforce host list, redirect refusal, outbound controlsHost tests
Excessive callsPer-client rate, concurrency, timeout, body, and response limitsLoad tests
Retry amplificationRetry only safe transient failures with capped backoffFailure injection
Malformed Salesforce responseContract and size validation; fail closedResponse tests
Cross-client response leakSupported MCP SDK; isolated request state; concurrency testsParallel tests
Sensitive telemetryLog field list, no bodies, retention policy, canary scanTelemetry scan
Unexpected MCP toolAgentforce Registry tool list; deployment inventory checkTool-list test
Supply-chain compromiseLocked dependencies, scans, SBOM, immutable artifactAttestation
Unsafe releaseStaged rollout, kill switch, revocation, independent rollbackRollback drill
  • FAIL is a completed evaluation, not a transport error.
  • UNABLE_TO_EVALUATE, ERROR, missing output, and adapter failure never become PASS.
  • MCP never claims to preserve the conversational user’s Salesforce access.
  • Removing Record Health Check Run prevents evaluation.
  • Ordinary Agentforce and MCP principals can receive only the four bounded completed-evaluation diagnosis fields; they cannot receive raw or administrator-only diagnostics.
  • Models cannot select event publication in version 1.
  • MCP exposes no generic query, Apex, record update, or metadata operation.
  • Logs exclude complete tool inputs and Apex responses.

Security, product, Apex, Agentforce, identity, MCP service, and operations owners must approve this model before production. Repeat review when tools, outputs, identities, scopes, objects, hosting, persistence, or publication behavior changes.