A patched research finding with a broader lesson
Zenity Labs disclosed research into an Agentforce attack chain it calls SalesBleed, in which instructions planted in a public Web-to-Lead submission could redirect an agent handling a normal lead-review task. The researchers say the chain could expose CRM data through automatically fetched content. Zenity reports that Salesforce fixed the described bypass, with the fix confirmed in August. This is a report of demonstrated vulnerabilities and remediation, not evidence presented here of a successful criminal breach.
The agent already had the access
The research emphasizes a trust-boundary problem: an agent could read externally supplied material while also having permission to query more sensitive business records. Zenity describes the combination of those permissions and an output-handling weakness as central to its demonstration. Our analysis is that an AI deployment review should start with the agent’s authority. Ask what it can read, which actions it can perform and whether incoming content can influence those actions. A reassuring chat response is not a substitute for understanding the permissions behind it.
Sales workflows make the question concrete
An e-commerce company evaluating an AI sales assistant should distinguish public customer inquiries from internal commercial records. A professional-services firm should examine the equivalent boundary between a prospect’s submission and confidential client information. These are proposed review questions; they do not imply those organizations use Agentforce or were affected. The business owner should specify the minimum information needed for each task before a technical team grants a broad connection to the CRM.
Test behavior at the boundary
We recommend a controlled evaluation with synthetic records and clearly defined pass-or-fail outcomes. Establish whether outside text can cause the assistant to reach information beyond the task, whether outputs initiate additional retrievals and what the audit trail records. Do not run exploit tests against systems without authorization. Ask the provider to document the current remediation status and the scope of any customer-side configuration work. The useful lesson from a patched disclosure is an improved approval process for future agents, not a claim that a now-fixed attack remains available.
Sources & further reading
Our practical suggestions are editorial guidance. Verify applicability against current source and vendor instructions.

