forcedotcom/sf-skills

dx-pkg-post-install-configure

Use this skill to automate managed package post-install configuration.

View source
Original skill document

Rendered from the source repository. Headings, examples, code, tables, links, and referenced images are preserved.

When to Use This Skill

Use when automating post-install configuration for any Salesforce managed package. This skill reads the package's post-install documentation, discovers available execution methods, and automates the configuration steps — including permission sets, object/field permissions, page layouts, Visualforce page access, and tab settings.

Input

  • Required: Package name (e.g., LMA, FMA, work.com)
  • Optional: Path to post-install doc (PDF, markdown, URL)

If no doc is provided, ask the user to supply it.

Workflow

Execute phases in order. Each phase must pass before proceeding.


Phase 1: Discover Available Execution Methods

Priority order:

  1. Org-native platform MCP servers (highest — direct org access via Headless 360)
  2. Claude Code external MCP servers (sf-sobject-all, sf-sobject-all-sb, etc.)
  3. sf CLI fallback (always available if authenticated)

Step 1A: Resolve org API version

Discover the org's current API version dynamically — never hardcode a version number:

bash
sf org display --target-org <alias> --json

From the JSON response, read result.apiVersion (e.g., "67.0"). Store this value and use it as v<apiVersion> in all subsequent REST paths. If the command fails, fall back to the minApiVersion declared in this skill's metadata (67.0).

Step 1B: Check for org-native platform MCP servers

Query the Tooling API for MCP server availability:

bash
sf api request rest "/services/data/v<apiVersion>/tooling/query?q=SELECT+Id,DeveloperName,MasterLabel+FROM+McpServerAccess" --target-org <alias>

Step 1C: Determine execution method

Check which Claude Code MCP tools are available and authenticated.

MCP tool prefixes by org type:

Org TypeTool Prefix
Productionmcp__sf-sobject-all__
Sandboxmcp__sf-sobject-all-sb__
Falcon Test (pc-rnd)mcp__sf-sobject-all-falcon__

If MCP needs auth, call the authenticate tool. If auth fails, fall back to sf CLI.


Phase 2: Verify Authentication & Org Identity

  1. Run a lightweight test query (SELECT Id, Name, IsSandbox FROM Organization)
  2. If MCP auth fails, automatically fall back to sf CLI
  3. Display org info and ask user to confirm before proceeding

Phase 3: Verify Package Installation

  1. Determine the package namespace (ask user if unknown)
  2. Check via Tooling API (InstalledSubscriberPackage) — do NOT use PackageLicense
  3. If package not found, stop and inform user

Phase 4: Read and Parse Post-Install Document

Read the provided document and extract discrete configuration steps.

Supported formats: PDF, markdown, URL (via WebFetch), pasted text.

Parsing approach:

  1. Extract each numbered/bulleted step from the document
  2. Present the extracted steps to the user for validation before proceeding

Phase 5: Classify Steps & Interactive Plan Review

For each step extracted from the doc, classify as Automated or Manual.

Automation capabilities reference

Via MCP (sobject-all) or sf CLI CRUD:

  • Record CRUD on any standard or custom object (PermissionSet, ObjectPermissions,

FieldPermissions, SetupEntityAccess, PermissionSetTabSetting, PermissionSetAssignment, etc.)

Via Metadata API retrieve/deploy (sf CLI):

  • Page layout modifications (add related lists, fields, sections)
  • Profile settings
  • Custom metadata type records

Via sf CLI Tooling API:

  • Tooling queries (InstalledSubscriberPackage, ApexPage, ApexClass, etc.)
  • Any REST-accessible Tooling operation

Manual (no API path — requires Setup UI):

  • System permissions not exposed via REST
  • Connected app OAuth configuration
  • Environment Hub linkage

Interactive approval

Present the classified plan and let the user choose:

  • "Approve all" — Execute all steps as planned
  • "Let me choose" — Select which steps to approve/skip
  • "I have questions" — Discuss specific steps before deciding

Phase 6: Execute Approved Steps

For each approved step, use the resolved execution method.

Execution method reference

OperationVia MCPVia sf CLI
SOQL querysoqlQuery toolsf data query --query "<SOQL>" --target-org <alias> --json
Create recordcreateSobjectRecord toolsf data create record --sobject <Object> --values "..." --target-org <alias> --json
Update recordupdateSobjectRecord toolsf data update record --sobject <Object> --record-id <id> --values "..." --target-org <alias> --json
Describe objectgetObjectSchema toolsf api request rest "/services/data/v<apiVersion>/sobjects/<Object>/describe" --target-org <alias>
Page layoutN/AMetadata API retrieve/deploy

Page layout modifications via Metadata API

Use sf project retrieve start → edit the layout XML → sf project deploy start.

Execution rules

  • Idempotency: Before creating any record, query to check if it already exists. Skip if so.
  • Report after each step: Show success count, skipped items, and reasons.
  • Automatic fallback: If MCP fails mid-execution, retry via sf CLI.
  • On failure: Report error, ask user to retry/skip/stop.

Phase 7: Guide Manual Steps (if any)

If any steps could not be automated, present each with Setup navigation instructions. Wait for user confirmation before proceeding to the next.


Phase 8: Summary

Display final summary with step-by-step status, method used, and any skipped items.


Error Handling

  • Auth failure mid-execution: Stop, ask user to re-auth, offer to resume
  • Duplicate record errors: Treat as "already configured", skip and continue
  • Permission errors: Report which permission is missing, suggest resolution
  • Unknown step type: Ask user to clarify, offer to mark as manual

Notes

  • Priority: org-native MCP > Claude Code MCP > sf CLI > manual
  • sf CLI is always a valid fallback for all CRUD and Tooling API operations
  • Page layout modifications are automated via Metadata API retrieve/deploy
  • Always verify org identity before making changes
  • All actions respect the authenticated user's permissions
from this repository

More skills

All skills
forcedotcom
Community

design-systems-slds-apply

Apply SLDS-compliant UI using the correct blueprints, styling hooks, utility classes, and icons. Use when building any UI that needs SLDS, choosing between Lightning Base Components and SLDS Blueprints, applying styling hooks for theming, using utility classes for layout and spacing, or selecting icons. Triggers include \"build a modal\", \"create a form\", \"data table\", \"SLDS styling\", \"style with hooks\", \"add an icon\".

installs
5
GitHub stars
948
Updated
8月28日
forcedotcom
Community

design-systems-slds-validate

Audit Lightning Web Components for SLDS design-system compliance and produce a scored quality report. Runs the SLDS linter and analyzes CSS for theming hook usage and pairing, scoring SLDS findings across categories into an overall grade. Use when asked to \"score my component's SLDS\", \"SLDS scorecard\", \"SLDS quality report\", \"audit SLDS compliance\", \"how good is my SLDS\", \"check SLDS quality\", \"rate my SLDS styling\", \"evaluate my component's SLDS\", \"is this component's SLDS ready to ship?\", \"look at my LWC for SLDS issues\", \"audit SLDS before I submit\", \"review my component's SLDS before code review\", or any time a user wants an SLDS quality assessment or SLDS production-readiness check on an LWC. Not for fixing violations (use design-systems-slds2-migrate), building new components (use design-systems-slds-apply), or accessibility/WCAG/ARIA audits (use experience-accessibility-validate).

installs
5
GitHub stars
948
Updated
8月28日
forcedotcom
Community

design-systems-slds2-migrate

Migrate Lightning Web Components from SLDS 1 to SLDS 2 by running the SLDS linter and fixing violations. Use this skill whenever users mention SLDS 2, SLDS uplift, linter violations, LWC token migration, class overrides, hardcoded CSS values that need SLDS hook replacement, or styling hook selection. Covers all styling hook categories — color, spacing, sizing, typography, borders, radius, and shadows. Also use when users mention no-hardcoded-values, no-slds-class-overrides, lwc-to-slds-hooks, no-deprecated-tokens-slds1, or ask about SLDS component migration — even if they don't explicitly say \"uplift\" or \"migration\".

installs
5
GitHub stars
948
Updated
8月28日
forcedotcom
Community

agentforce-architecture-analyze

Declared architecture snapshot for one Agentforce agent: planner, topics, actions, flows, Apex, prompt templates, and NGA plugins. Renders a human-readable architecture document and Mermaid invocation graph from design-time metadata (not runtime audit rows). TRIGGER when user asks to describe, diagram, inventory, audit, document, or diff (e.g. v3 vs v5) the architecture / action tree / topic structure / tool inventory of a specific agent by agent API name in a specific org. DO NOT TRIGGER for runtime session traces, conversation transcripts, generation timings, or gateway audit chains — this skill reads design-time metadata only (use agentforce-d360-analyze for session traces).

installs
4
GitHub stars
948
Updated
8月28日