Enterprise AI has changed the security boundary. A Salesforce agent can read CRM records, retrieve knowledge, invoke actions, and interact with external systems. That makes the prompt a potential control plane, not merely a conversational input. Prompt injection exploits this shift. Instead of manipulating a database query, an attacker manipulates the instructions an LLM interprets. This leads to malicious instructions to alter model behavior, expose sensitive information, or influence connected functions. Direct attacks come from user input, while indirect prompt injection comes from external content the model later reads, such as documents, websites, emails, or retrieved knowledge.

For Salesforce teams, the implication of these Agentforce security risks is practical: they need to go beyond identity, permissions, and data access when it comes to preventing these risks. So, how to prevent such severe LLM security vulnerabilities? Especially when the agent’s entire input-to-action path becomes part of the attack surface. This blog will cover prompt injection Salesforce risks, impact and share best practices to prepare you for situations when an AI agent attack surfaces.
What Is a Prompt Injection?
Prompt injection occurs when untrusted content causes an LLM to follow instructions that conflict with its intended task. In an agentic system, the risk increases because the model may have tools and permissions that let it act on the result.
How to Know Your Agentforce Has Been Prompt Injected
For better prevention, you must identify signs that prompt injection Salesforce teams should look out for:
- Unexpected actions: Agents trigger updates/calls to CRM/executing tools that weren’t requested by the user.
- Anomalous responses: Using instructions or content that the user didn’t provide, often based on external documents or knowledge bases.
- Data leakage attempts: Agent discloses sensitive data from the CRM, configurations, or instructions beyond the scope of the query.
- Redirected behavior: The agent follows links or APIs outside the trusted URL list, indicating unsafe external access.
- Context poisoning indicators: Persistent changes in agent reasoning or repeated references to malicious content across sessions.
Understanding the AI Agent Attack Surface in Agentforce
An AI agent attack surface includes every place where untrusted input can influence model reasoning, tool selection, data retrieval, or downstream actions. For Agentforce, that can include:
- User prompts and conversation history
- CRM and Data Cloud records used for grounding
- Knowledge articles and uploaded files
- External websites, documents, emails, and API responses
- Agent instructions, topics, actions, and connected tools
- URLs and external systems the agent can access
Salesforce provides protections through the Einstein Trust Layer, including prompt injection detection, system policies, secure data retrieval, audit capabilities, and trusted URL controls. But the user must treat Agentforce security as a shared responsibility: Salesforce secures the platform, while customers configure permissions, guardrails, monitoring, and agent-specific controls.
Indirect Prompt Injection: Is Your Salesforce Agentforce AI the New Attack Surface?
Indirect prompt injection is particularly relevant to CRM environments because agents increasingly consume information they did not receive directly from the user. A malicious instruction could be embedded in a knowledge article, customer-submitted document, webpage, or retrieved source. When the agent processes that material, the content can attempt to redirect its behavior.
The attack path can be simple:
What Are the Key Agentforce Security Risks?
Data exposure:
The agent may be manipulated into revealing information beyond the request.
Excessive agency:
Over-permissioned tools can turn a manipulated response into a real business action.
Instruction leakage:
Attackers may attempt to extract system instructions or configuration details.
Context poisoning:
Malicious content can influence reused or persistent context.
Unsafe external access:
Using third-party links or APIs can cause data leaks or unauthorized use.
Prompt Injection Risks: 7 Steps to Keep Your Agents Secure
Treat External Content as Untrusted
Classify user input, retrieved documents, websites, emails, and API responses as data, not instructions. Define trust boundaries before content enters the agent context to reduce prompt injection Salesforce exposure.
Apply Least Privilege
Give the agent only the Salesforce objects, fields, actions, URLs, and services required for its function. Salesforce recommends customer-side controls such as least-privilege permissions and agent guardrails.
Validate Actions, Not Only Prompts
A prompt filter may spot suspicious text, but controls must also check if the action matches what the user asked for. Critical tasks should only continue after double verification or approval from human agents.
Restrict Outbound Destinations
Salesforce Trusted URLs controls reduce the risk of malicious links and outbound requests following prompt injection. In February 2026, Salesforce removed default domain *.salesforce.com. Customers are now expected to create an explicit list of domains their agents need. This change reduces exposure, limits unnecessary endpoints, and enforces tighter control over external access.
Adversarial Input Test
Security testing should include direct injection, indirect injection through knowledge and documents, tool manipulation, data-exfiltration attempts, and unauthorized-action scenarios. OWASP recommends penetration testing and breach simulations for LLM applications.
Monitor and Audit Agent Behavior
Track prompts, responses, tool calls, permission use, blocked actions, and anomalies. Detailed logs strengthen Salesforce security assessment and help contain Agentforce security risks tied to LLM security vulnerabilities.
Embed Security into Lifecycle
Integrate security reviews across design, testing, rollout, and updates. Embedding controls early limits indirect prompt injection CRM risks and aligns with Salesforce Security & Compliance Consulting standards.
Agentforce Security Assessment Checklist
- Data Sources: Review all agent inputs to confirm only trusted records and documents are consumed.
- Instructions: Examine agent instructions to prevent leakage or manipulation.
- Permissions: Audit access rights to enforce least-privilege across Salesforce objects and fields.
- Actions: Validate tool and action execution against approved workflows.
- Integrations: Inspect APIs and external systems for unsafe exposure.
- External URLs: Restrict outbound requests to a defined trusted list.
- Human Approval: Define checkpoints for sensitive or high-impact operations.
- Logging: Enable capture of prompts, responses, tool calls, and blocked actions.
- Failure Paths: Map recovery processes to ensure safe handling of injection attempts.
- Blast Radius: Test containment controls to limit manipulated instructions.
- Context Poisoning: Monitor for malicious influence across persistent agent sessions.
- Governance: Include compliance checks alongside technical controls before deployment.
Wrapping It Up
Prompt injection is becoming an enterprise application security issue because AI agents can translate manipulated language into access, decisions, and actions. For Salesforce organizations, Agentforce security requires more than prompt hygiene. It requires a deliberate review of the agent’s attack surface, trust boundaries, permissions, integrations, and operational controls.
Seeking a Salesforce Security & Compliance Consulting partner can help you assess these controls, identify agentic AI exposure, and build a security framework aligned with enterprise governance requirements.
+1-480-241-8198
+44-7428758945
+61-1300-332-888
+91 9811400594

