Skip to content

feat: Run Script action #145

Description

@Lacah

Create a new Flow Designer custom action called “Run Script”, which allows dynamic server-side script execution within flows.

This action should accept a script input (string) that contains arbitrary server-side JavaScript code, execute it, and return its output as an action output.

The purpose of this feature is to give builders and developers a lightweight, reusable utility to run ad-hoc scripts directly in Flow Designer without creating a dedicated Script Action or Script Include. It is particularly useful for rapid prototyping, conditional logic, and development workflows.

Activity

  1. jiteshmalik commented on Oct 10, 2025

    @jiteshmalik
    Contributor

    @Lacah This request definitely made me pause and think through some important questions—such as who gets access to this, what privilege level the scripts run at, whether it opens doors for ACL bypasses, and how it aligns with compliance requirements like SOX or PCI-DSS. But honestly, the technical puzzle was interesting enough that I decided to dig into it anyway.

    Implementation Challenge:
    Turns out ServiceNow's JavaScript APIs make this trickier than expected. The eval() function only works in global scope, and GlideScopedEvaluator (which would be the "proper" scoped option) needs you to save the script to a GlideRecord first before it can run anything. There's no clean way to just execute a script string from memory in a scoped app—you either have to persist it to a table or work in global scope, and both of those options bring their own security headaches.

    So I have tried a custom action with a flexible approach that uses a temporary table to handle the GlideScopedEvaluator requirement.

  2. linked a pull request that will close this issueExecute Script Action #155on Oct 10, 2025
  3. SapphicFire commented on Oct 12, 2025

    @SapphicFire
    Contributor

    Jitesh has come up with a great solution to this, and I welcome other contributors who would like to introduce their own approaches and implementations. At this stage, I am not comfortable with merging such actions into the repository due to how potentially destructive they are and the commensurate increase in risk they present. However, I am happy to mark such items as hacktoberfest-accepted. Good luck, and happy hacking!

  4. GokulkumarV commented on Oct 17, 2025

    @GokulkumarV
    Contributor

    Hi @Lacah,

    Whenever we have similar use-case, I recommend my Devs to create a flow variable and use 'Set Flow Variables' to achieve this.
    Thought of sharing this if it might be helpful to this issue scenario.

    Image
  5. Lacah commented on Oct 17, 2025

    @Lacah
    ContributorAuthor

    Definitely a good workaround @GokulkumarV!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions