Borrowing it
Nothing to install: this file belongs to Damecek/salesforce-mcp-lib. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/Damecek/salesforce-mcp-lib/main/CLAUDE.mdgit clone --depth 1 https://github.com/Damecek/salesforce-mcp-libWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/damecek/salesforce-mcp-lib/claude-md)<a href="https://agentmods.dev/instructions/damecek/salesforce-mcp-lib/claude-md"><img src="https://agentmods.dev/badge/instructions/damecek/salesforce-mcp-lib/claude-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.01062 | $0.01062 |
| Opus 5 | $0.00531 | $0.00531 |
| Sonnet 5 | $0.00212 | $0.00212 |
| Haiku 4.5 | $0.00106 | $0.00106 |
Grade A, and why
salesforce-mcp-lib CLAUDE.md scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Runs shell commandslowCapability
Expected in a hook, worth knowing in a rule or an instructions file.
- TypeScript ES2022, Node.js >= 20.0.0 + Zero production dependencies. Node.js built-in modules only (`node:http`, `node:https`, `node:fs`, `node:path`, `node:crypto`, `node:os`, `node:child_process`, `node:readline`, `n How it starts
The opening of the file, as written. The whole thing — 78 lines — stays where its author put it; the contents beside it link to each section on GitHub.
salesforce-mcp-lib Development Guidelines
Auto-generated from all feature plans. Last updated: 2026-04-08
Active Technologies
-
TypeScript ES2022, Node.js >= 20.0.0 + Zero production dependencies. Node.js built-in modules only (
node:http,node:https,node:fs,node:path,node:crypto,node:os,node:child_process,node:readline,node:url) (003-per-user-auth) -
File-based token persistence in
~/.salesforce-mcp-lib/tokens/(0600 permissions) (003-per-user-auth) -
Apex (Salesforce API 65.0) + TypeScript (ES2022, Node.js >= 20) + Zero external dependencies. Apex uses platform-native APIs only. TypeScript uses Node.js built-in modules only (no production npm dependencies). JSON-RPC 2.0 core is implemented in-repo, not imported. (001-apex-mcp-server)
Project Structure
packages/salesforce-mcp-lib/src/
index.ts # CLI entry point (login subcommand + MCP server)
config.ts # CLI argument / env-var parser
types.ts # Shared type definitions (AuthConfig, AuthMode, etc.)
errors.ts # Error class hierarchy (SalesforceAuthError + subclasses)
oauth.ts # Client credentials OAuth flow + ClientCredentialsStrategy
authStrategy.ts # AuthStrategy interface + PerUserAuthStrategy + factory
perUserAuth.ts # Authorization Code flow (PKCE, token exchange, browser)
callbackServer.ts # Local HTTP server for OAuth redirect callback
tokenStore.ts # File-based token persistence (~/.salesforce-mcp-lib/tokens/)
mcpBridge.ts # JSON-RPC forwarding to Salesforce Apex endpoint
stdio.ts # Stdio transport + levelled logger
packages/salesforce-mcp-lib/tests/
*.test.ts # Unit tests (node:test runner)
Commands
cd packages/salesforce-mcp-lib && npm test && npm run lint
Code Style
Apex (Salesforce API 65.0) + TypeScript (ES2022, Node.js >= 20): Follow standard conventions
Recent Changes
- 003-per-user-auth: Implemented per-user OAuth 2.0 Authorization Code flow with PKCE. New modules: authStrategy.ts, perUserAuth.ts, callbackServer.ts, tokenStore.ts.
--client-secretis now optional. Auth mode auto-detected from config. Login subcommand:salesforce-mcp-lib login. File-based token persistence in~/.salesforce-mcp-lib/tokens/. Five specific error subclasses (InvalidCredentialsError, InsufficientAccessError, ConsentDeniedError, SessionExpiredError, ConnectivityError). Backward compatible with client credentials flow.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 78 lines · 1,062 tokens per session scan A b2ba9d6091a2
salesforce-mcp-lib CLAUDE.md is an instructions file published in the GitHub repository Damecek/salesforce-mcp-lib (19 stars, last pushed 4mo ago), licensed MIT. It adds 1,062 tokens to every session, about $0.0053 per session on Opus 5. A static security scan graded it A with 1 finding (runs shell commands). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.