What it requires. Text that a stranger can write - web-form fields, inbound email bodies, case descriptions, chat transcripts - is grounded into a prompt for an agent that can take actions or emit outbound links.
Why it matters. ForcedLeak (CVSS 9.4, Noma Labs, September 2025) submitted instructions through Web-to-Lead which executed later during an ordinary employee interaction and exfiltrated CRM data. Salesforce patched it - re-securing the domain and enforcing a URL allowlist on agent output - and that patch is the vendor's own evidence that the platform did not prevent it. The documentation describes prompt defence as heuristics that reduce the odds, not eliminate them. The check is not whether the Trust Layer is on; it is which untrusted fields reach a grounded prompt and what the agent can do once they are there.
How to fix it. Separate untrusted inbound fields from grounded prompts, or strip them to a controlled vocabulary before grounding. Where they must be grounded, restrict the agent's action scope on that surface.
Source. ForcedLeak, Noma Labs, September 2025 (CVSS 9.4); Salesforce Trust Layer documentation
Is this rule worth checking?
Votes and comments are published here. We read them, and we publish what we change with the reasoning — a vote does not move a rule on its own.
