Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add forcedotcom/sf-skillsnpx agentmods add plugins/forcedotcom/sf-skills/salesforce-developmentgit clone --depth 1 https://github.com/forcedotcom/sf-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/forcedotcom/sf-skills/salesforce-development)<a href="https://agentmods.dev/plugins/forcedotcom/sf-skills/salesforce-development"><img src="https://agentmods.dev/badge/plugins/forcedotcom/sf-skills/salesforce-development.svg" alt="Measured on agentmods" height="20"></a>Grade A, and why
salesforce-development scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 281 lines — stays where its author put it; the contents beside it link to each section on GitHub.
{
"name": "salesforce-development",
"displayName": "Salesforce Development",
"version": "2.1.0",
"description": "Build Salesforce apps and agents using these core building blocks: metadata, Apex, deploy/retrieve, security, reporting, and generated installed-versus-available capability discovery.",
"author": { "name": "Salesforce", "url": "https://github.com/forcedotcom/sf-skills" },
"license": "Apache-2.0",
"homepage": "https://github.com/forcedotcom/sf-skills/tree/main/plugins/builder/salesforce-development",
"repository": "https://github.com/forcedotcom/sf-skills.git",
"keywords": ["salesforce", "apex", "flow", "soql", "metadata", "deploy"],
"dependencies": [],
"userConfig": {
"ui_mode": {
"type": "string",
"title": "Salesforce development UI mode",
"description": "Ambient UI: full (default), compact, plain semantic text, or off. Explicit commands and safety guidance remain available.",
"default": "full"
},
"plugin_match_sensitivity": {
"type": "string",
"title": "Uninstalled-plugin recommendation sensitivity",
"description": "How readily this plugin proposes an uninstalled Salesforce plugin matching your task: off (never), low, standard (default), high, or a custom number from 1.0-10.0. Change it any time from within a session with /salesforce-development:plugin-recommendations.",
"default": "standard"
}
},
"skills": "./skills/",
"commands": "./commands/",
"hooks": {
"SessionStart": [
{
"matcher": "*",
"hooks": [
{
"type": "command",
"command": "\"${CLAUDE_PLUGIN_ROOT}\"/scripts/sf-context detect",
"statusMessage": "Loading local Salesforce project context…"
},
{
"type": "command",
"command": "\"${CLAUDE_PLUGIN_ROOT}\"/scripts/sf-context telemetry-capture session_start"
}
]
}
],
"PreToolUse": [
{
"matcher": "BasWhat it installs
The manifest is a name and a version. 37 skills, 13 commands, 2 agents, 3 MCP servers travel with it, and installing the plugin installs all of them — 5,939 tokens a session between them. Each is measured on its own page, and each can be installed alone.
- Skill automation-flow-generate A 106 tokens
- Skill dx-code-analyzer-configure A 226 tokens
- Skill dx-code-analyzer-run A 239 tokens
- Skill dx-org-manage A 225 tokens
- Skill platform-apex-generate A 122 tokens
- Skill platform-custom-field-generate A 194 tokens
- Skill platform-metadata-api-context-get A 215 tokens
- Skill platform-flexipage-generate A 185 tokens
- Skill platform-lightning-app-coordinate A 79 tokens
- Skill platform-sharing-rules-generate A 157 tokens
- Skill platform-value-set-generate A 170 tokens
- Skill platform-apex-anonymous-run A 159 tokens
- Skill platform-custom-object-generate A 157 tokens
- Skill platform-custom-report-type-generate A 139 tokens
- Skill platform-lsp-integrate A 207 tokens
- Skill platform-manifest-generate A 176 tokens
- Skill platform-apex-test-generate A 135 tokens
- Skill platform-architecture-analyze A 204 tokens
- Skill platform-environment-validate A 160 tokens
- Skill platform-metadata-deploy A 110 tokens
- Skill platform-soql-query A 132 tokens
- Skill dx-project-create A 176 tokens
- Skill platform-apex-logs-debug A 89 tokens
- Skill platform-apex-test-run A 124 tokens
- Skill platform-custom-tab-generate A 86 tokens
- Skill platform-list-view-generate A 97 tokens
- Skill platform-report-generate A 175 tokens
- Skill platform-capability-search A 99 tokens
- Skill platform-permission-set-generate A 62 tokens
- Skill platform-quick-deploy A 117 tokens
- Skill platform-deploy-validate A 106 tokens
- Skill platform-custom-application-generate A 93 tokens
- Skill platform-sharing-owd-configure A 156 tokens
- Skill platform-metadata-retrieve A 147 tokens
- Skill platform-validation-rule-generate A 81 tokens
- Skill dx-code-analyzer-custom-rule-create C 228 tokens
- Skill platform-destructive-deploy C 102 tokens
- Command reset-source-tracking A 43 tokens
- Command setup A 47 tokens
- Command login A 26 tokens
- Command plugin-recommendations A 20 tokens
- Command set-default A 34 tokens
- Command logout A 20 tokens
- Command telemetry A 24 tokens
- Command discover A 27 tokens
- Command plugin-install A 18 tokens
- Command org A 20 tokens
- Command project A 30 tokens
- Command status A 22 tokens
- Command welcome A 33 tokens
- Agent architecture-review A 100 tokens
- Agent salesforce-dev A 40 tokens
- MCP server salesforce-api-context A not measured
- MCP server salesforce-metadata-experts A not measured
- MCP server salesforce-lsp A not measured
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today First seen · 281 lines scan A c21c79de64aa
salesforce-development is a plugin published in the GitHub repository forcedotcom/sf-skills (961 stars, last pushed yesterday), licensed Apache-2.0. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other plugins, from other repositories
nextjs
Official Next.js skills: adopt and optimize Cache Components, adopt Partial Prefetching, and verify runtime behavior against a running dev server.
claude-plugins-official marketplace
Directory of popular Claude Code extensions including development tools, productivity plugins, and MCP integrations.
humanizer
Rewrite AI-sounding text so it reads naturally without changing what it says.
knowledge-work-plugins marketplace
Plugin marketplace listing 98 plugins: noibu, productivity, enterprise-search, cowork-plugin-management, sales.
container
Teaches Claude container's command surface and how it maps to Docker, Lima, Colima, and Podman on macOS.
mattpocock-skills
Matt Pocock's agent skills for real engineering: grilling, spec/ticket flows, TDD, code review, domain modelling and more. Plug-and-play, not vibe coding.