All authors

Claude Skills by PranavNagrecha
github.com/PranavNagrecha1,088 skills0 installs2,308 views
- Gdpr Data PrivacyUse this skill when implementing GDPR or CCPA data privacy controls in Salesforce: Individual sObject linkage, consent tracking, Right to Be Forgotten (RTBF) requests, data subject request handling, and Privacy Center configuration. Trigger keywords: GDPR, data privacy, consent management, right to erasure, Individual object, ContactPointConsent, ShouldForget, data subject request, Privacy Center, data portability. NOT for general data quality cleanup, duplicate management, field-level encryp...Votes: 0GitHub stars: 15
- Guest User Security AuditAuditing the security posture of an Experience Cloud (Community) site's Guest User. Covers the post-Spring '21 secure-by-default lockdown (object permissions removed, sharing rule grants required for any access), the Guest User profile permissions to remove (View All Data, Modify All Data, Manage Users, etc.), guest sharing rules, the Run-As-Guest test, OWASP A01 (Broken Access Control) mapping, and the standard set of leakage vectors (Apex with `without sharing`, Aura / LWC `@AuraEnabled` me...Votes: 0GitHub stars: 15
- Guest User SecurityUse when hardening the Experience Cloud guest user profile, controlling unauthenticated access to records and Apex, or investigating data exposure through guest SOQL. Covers object permissions, sharing model enforcement for unauthenticated users, and Apex execution context. NOT for Experience Cloud site creation (use Experience Cloud skills) or for authenticated external user security (use security/experience-cloud-security).Votes: 0GitHub stars: 15
- Ip Range And Login Flow StrategyDesign and implement Salesforce Login Flows (Screen Flows assigned to profiles or Experience Cloud sites) that run post-authentication to enforce conditional MFA, IP-based branching, terms-of-service acceptance, or user data collection. Covers Login Flow creation in Flow Builder, profile/site assignment, IP-aware decision logic, and ConnectedAppPlugin extension points. NOT for static IP allowlisting or profile Login IP Ranges (see network-security-and-trusted-ips), org-wide session policies, ...Votes: 0GitHub stars: 15
- Ip Relaxation And RestrictionDesign IP-based access controls: profile login IP ranges, org-wide trusted IPs, IP relaxation per profile, and the interaction with MFA and SSO. Trigger keywords: login IP range, trusted IP, IP relaxation, restricted IP, IP allowlist, login hours. Does NOT cover: network-layer firewalling, corporate VPN design, or Shield Event Monitoring.Votes: 0GitHub stars: 15
- Login ForensicsInvestigate Salesforce login activity using LoginHistory, IdentityVerificationHistory, and Login Forensics (Event Monitoring add-on): reconstruct per-user login timelines, identify failed logins, analyze source IPs, review identity verification events, and configure Login Flows for step-up authentication. NOT for MFA setup (use org-setup-and-configuration). NOT for downloading EventLogFile CSVs or configuring real-time threat detection (use event-monitoring).Votes: 0GitHub stars: 15
- Mfa Enforcement PatternsDesign MFA enforcement: auto-enablement, Salesforce Authenticator rollout, exceptions, service accounts, API-only users, SSO interop, and audit. Trigger keywords: MFA, multi-factor, two-factor, Salesforce Authenticator, MFA exception, MFA SSO, api-only MFA. Does NOT cover: end-user password policies, device-trust posture, or non-Salesforce IdP configuration.Votes: 0GitHub stars: 15
- Mfa Enforcement StrategyOrg-wide MFA rollout strategy, phased enablement, exception governance, and audit. Triggers: MFA rollout plan, MFA policy, MFA governance. NOT for per-user-type enforcement patterns — use security/mfa-enforcement-patterns.Votes: 0GitHub stars: 15
- Network Security And Trusted IpsConfigure and audit Salesforce network security controls — trusted IP ranges (org-wide Network Access), login IP ranges on profiles, CSP Trusted Sites for Lightning components, CORS allowlists for external JavaScript, and TLS requirements — and troubleshoot login-blocked-by-IP or CSP violation errors. NOT for org-wide session settings, MFA configuration, or real-time Transaction Security Policies.Votes: 0GitHub stars: 15
- Oauth Redirect And Domain StrategyDesign Connected App OAuth callback URLs, My Domain naming, Enhanced Domains cutover, and cross-environment redirect handling. Trigger keywords: oauth redirect uri, connected app callback, my domain, enhanced domains, sandbox url change, oauth login host. Does NOT cover: end-user login flow UX, Experience Cloud branding, or SAML-only SSO configuration.Votes: 0GitHub stars: 15
- Oauth Token ManagementUse when work depends on how Salesforce OAuth access and refresh tokens are issued, refreshed, rotated, revoked, or introspected for a Connected App or API client—including unexpected logouts, invalid_grant after refresh, or designing token incident response. NOT for choosing which OAuth grant or Connected App flow to implement (use integration/oauth-flows-and-connected-apps), Named Credential packaging (use integration/named-credentials-setup), or broad Connected App IP and PKCE policy harde...Votes: 0GitHub stars: 15
- Org Hardening And Baseline ConfigUse when defining or reviewing baseline org hardening settings, especially Security Health Check gaps, clickjack and browser protections, CSP and CORS governance, password/session policies, network restrictions, and release-update hygiene. NOT for feature-level app permissions or record-sharing design — use security/security-health-check.Votes: 0GitHub stars: 15
- Permission Set Groups And MutingUse when designing or reviewing permission-set-group architecture, especially profile minimization, group composition, muting strategy, and migration away from profile-heavy security models. Triggers: 'permission set group', 'muting permission. NOT for record-sharing design or CRUD/FLS review in Apex code — use admin/permission-set-architecture.Votes: 0GitHub stars: 15
- Platform EncryptionUse this skill when deciding which Salesforce fields to encrypt at rest, choosing between deterministic and probabilistic schemes, managing tenant secrets and keys (including BYOK and Cache-Only Keys), and satisfying compliance mandates for data-at-rest encryption. NOT for TLS/transport encryption, Classic Encrypted Text fields, or field masking without Shield. Trigger keywords: Shield Platform Encryption, data at rest, AES-256, tenant secret, BYOK, key rotation, encrypted search.Votes: 0GitHub stars: 15
- Privileged Access ManagementDesign just-in-time elevation, break-glass accounts, and audit trails for Modify All Data / System Admin / Customize Application permissions. NOT for regular permission set design.Votes: 0GitHub stars: 15
- Recaptcha And Bot PreventionUse when configuring reCAPTCHA on Web-to-Case, Web-to-Lead, Experience Cloud forms, or Headless Identity flows, or when designing bot-mitigation strategies for Salesforce public-facing surfaces. Triggers: 'enable reCAPTCHA on Web-to-Case', 'bot spam submissions on my Experience Site', 'Headless Identity reCAPTCHA v3 setup'. NOT for AppExchange security review (use secure-coding-review-checklist), NOT for session-level login security policies (use session-management-and-timeout), NOT for IP-ra...Votes: 0GitHub stars: 15
- Record Access TroubleshootingDiagnose why a user can or cannot see/edit a record: UserRecordAccess SOQL, Why Can a User Access This Record debug log, OWD, role hierarchy, sharing rules, manual/team/apex shares, implicit parent share. NOT for field-level security (use field-level-security-audit). NOT for designing sharing (use sharing-selection decision tree).Votes: 0GitHub stars: 15
- Salesforce Shield DeploymentRoll out Shield (Platform Encryption + Event Monitoring + Field Audit Trail) end-to-end, sequencing feature enablement to avoid data lockout. NOT for Classic Encryption or general PE design.Votes: 0GitHub stars: 15
- Sandbox Data MaskingUse this skill when configuring or reviewing Salesforce Data Mask to protect PII/PHI in partial or full copy sandboxes after a refresh. Trigger keywords: data mask, sandbox masking, PII in sandbox, GDPR sandbox, HIPAA non-production, mask contacts, obfuscate fields non-production. NOT for sandbox refresh mechanics (use sandbox-refresh-and-templates), NOT for production data anonymization, NOT for Shield Platform Encryption at rest.Votes: 0GitHub stars: 15
- Scim Provisioning IntegrationUse when designing or reviewing SCIM-based user lifecycle provisioning into Salesforce from Okta, Azure AD / Entra, or another IdP — create/update/deactivate, group-to-permission-set mapping, attribute mapping, and deprovisioning semantics. Triggers: 'scim provisioning', 'okta scim salesforce', 'entra salesforce provisioning', 'user deactivation automation', 'group to permission set mapping'. NOT for SSO/authentication setup (see single-sign-on skills).Votes: 0GitHub stars: 15
- Secure Coding Review ChecklistUse this skill to audit Apex, Visualforce, LWC, and Aura code for Salesforce security review readiness — covering CRUD/FLS enforcement, SOQL injection, XSS, CSRF, and open redirects. NOT for network-level penetration testing, Shield Platform Encryption key management, or general org permission set design.Votes: 0GitHub stars: 15
- Security Health CheckUse when running, interpreting, or acting on Salesforce Security Health Check results — reading the score, understanding risk categories, evaluating specific settings, creating or importing a custom baseline, querying the Tooling API programmatically, or planning remediation from findings. Triggers: 'security health check score', 'health check failing settings', 'custom baseline', 'remediate health check findings', 'fix risk'. NOT for org hardening implementation, permission model design, or ...Votes: 0GitHub stars: 15
- Security Incident ResponseWhen to use: active or suspected Salesforce org compromise, unauthorized access investigation, attacker containment, forensic evidence collection from EventLogFile/LoginHistory, session revocation, OAuth token cleanup, eradication of attacker persistence, and post-incident recovery verification. Trigger keywords: org compromised, suspicious login, attacker access, session revocation, forensic investigation, breach response, event log forensics, login anomaly investigation, incident response r...Votes: 0GitHub stars: 15
- Service Account Credential RotationUse when designing credential rotation for integration users, connected apps, named credentials, and OAuth client secrets in Salesforce. Covers rotation cadence, zero-downtime handover, secret storage, and detection of stale credentials. Triggers: 'rotate integration user password', 'connected app secret rotation', 'named credential rotation', 'stale service account', 'zero downtime secret rotation'. NOT for end-user password policies.Votes: 0GitHub stars: 15
- Session High Assurance PoliciesEnforce step-up authentication for sensitive pages/objects using High Assurance session level and login flow policies. NOT for initial MFA enrollment UX.Votes: 0GitHub stars: 15
- Session Management And TimeoutUse this skill when configuring session timeout values, concurrent session limits, session IP locking, or logout behavior in Salesforce. Covers org-wide session settings, profile-level overrides, Connected App session policies, and Metadata API SecuritySettings deployment. NOT for OAuth token refresh flows, login IP ranges, or MFA/identity-provider configuration.Votes: 0GitHub stars: 15
- Shield Event Log Retention StrategyUse when designing Salesforce Shield Event Monitoring retention, SIEM routing, and storage-tier strategy — which event types to keep, for how long, where, and how to answer audit queries across hot/warm/cold tiers. Triggers: 'shield event log retention', 'route event monitoring to splunk', 'how long to keep login history', 'siem salesforce integration', 'event monitoring storage tier'. NOT for enabling Shield (see salesforce-shield-deployment).Votes: 0GitHub stars: 15
- Shield Kms Byok SetupConfigure Shield Platform Encryption with customer-supplied (BYOK) or customer-held (Cache-Only Key Service) tenant secrets, rotate them, and recover. NOT for Classic Encryption or field masking.Votes: 0GitHub stars: 15
- Sso Saml TroubleshootingDiagnosing broken SAML SSO into Salesforce — IdP-initiated vs SP-initiated flows, signing-certificate validity / expiry, NameID format mismatches, RelayState handling, audience / entityId / issuer mismatches, clock skew, the SAML Assertion Validator in Setup, the Login History debug log, and the My Domain prerequisite for SSO. Covers the standard diagnostic loop: read the SAML response, identify which check failed, fix at the IdP or SP. NOT for OAuth / OpenID Connect SSO (see security/oauth-o...Votes: 0GitHub stars: 15
- Transaction Security PoliciesTransaction Security policy creation and configuration: condition builder, enhanced policies, enforcement actions (block, MFA, notification, end session), real-time monitoring mode, and policy troubleshooting. NOT for Event Monitoring log analysis or Shield Event Monitoring setup (use event-monitoring). NOT for Apex testing or debug-log analysis.Votes: 0GitHub stars: 15
- Visualforce Security And ModernizationUse when hardening or modernizing legacy Visualforce pages — covers the platform CSRF token model and when disabling it is a security regression, view state encryption guarantees and the 170 KB ceiling, FLS/CRUD enforcement gaps on `<apex:outputField>` and on getters that return sObjects, `<apex:includeScript>` interaction with the org Content Security Policy, hosting LWC inside a VF page via `lightning:container` / `lightning-out`, and the retire-vs-harden-vs-leave-alone decision for an inve...Votes: 0GitHub stars: 15
- Xss And Injection PreventionUse when writing or reviewing Visualforce pages, Apex controllers, or LWC components that output user-supplied data, build dynamic queries, or construct HTTP responses. Triggers: 'XSS in Visualforce', 'SOQL injection vulnerability', 'how to encode output in Apex', 'JSENCODE Visualforce', 'open redirect prevention'. NOT for Apex CRUD/FLS enforcement (use soql-security or apex-crud-and-fls), NOT for Shield encryption (use shield-encryption-key-management), NOT for AppExchange security review pr...Votes: 0GitHub stars: 15
- Salesforce AdminRouter for the 261 SfSkills `admin` skill packages. Declarative Salesforce configuration: objects, fields, record types, page layouts, permission sets, reports, the record-access model (OWD, role hierarchy, sharing rules), and the requirements work that precedes them. Use when the request mentions custom object, custom field, picklist, record type, page layout, permission set, profile, validation rule, report, dashboard, queue, approval process, user setup, sharing rule, org-wide default, OWD...Votes: 0GitHub stars: 15
- Salesforce AgentforceRouter for the 53 SfSkills `agentforce` skill packages. Agentforce and Einstein: agents, topics, actions, prompt templates, grounding, guardrails, evaluation and production readiness. Use when the request mentions Agentforce, agent topic, agent action, prompt builder, Einstein, Trust Layer, grounding, RAG, guardrails, agent evaluation, prompt injection. Finds and opens the exact skill package to read; it does not contain the guidance itself.Votes: 0GitHub stars: 15
- Salesforce ApexRouter for the 159 SfSkills `apex` skill packages. Apex and SOQL: triggers, Apex governor limits, async processing, OUTBOUND HTTP callouts, security enforcement, and test patterns. Owns calling an external API FROM Salesforce; salesforce-integration owns inbound. Generic nightly scheduling without naming code belongs to salesforce-flow. Codebase security review belongs to salesforce-security. NOT for SOSL — use salesforce-data. Use when the request mentions Apex, trigger, SOQL, Apex governor ...Votes: 0GitHub stars: 15
- Salesforce ArchitectRouter for the 106 SfSkills `architect` skill packages. Solution and platform architecture: multi-org strategy, scalability limits, licensing, Well-Architected reviews and architecture decision records. Use when the request mentions architecture, solution design, ADR, Well-Architected, scalability, large data volume, multi-org, licensing, tenant isolation, HA/DR, technical debt. Finds and opens the exact skill package to read; it does not contain the guidance itself.Votes: 0GitHub stars: 15
- Salesforce DataRouter for the 101 SfSkills `data` skill packages. Data model, data movement and data quality: migrations, bulk loads, query optimisation, deduplicating at volume, archival. Ordinary-volume duplicate cleanup and prevention use salesforce-admin; come here for hundreds-of-thousands+ dedup or third-party tools. LDV architecture uses salesforce-architect. Use when the request mentions data model, data migration, data load, Data Loader, Bulk API, external id, deduplication at volume, archival, SOS...Votes: 0GitHub stars: 15
- Salesforce DevopsRouter for the 70 SfSkills `devops` skill packages. Salesforce delivery: source tracking, packaging, branching, CI/CD pipelines, environment strategy and deployment troubleshooting. Use when the request mentions deploy, deployment, sfdx, sf CLI, scratch org, sandbox, unlocked package, change set, CI/CD, GitHub Actions, release, rollback, source tracking. Finds and opens the exact skill package to read; it does not contain the guidance itself.Votes: 0GitHub stars: 15
- Salesforce FlowRouter for the 63 SfSkills `flow` skill packages. Flow Builder: record-triggered, screen, scheduled and orchestration flows, bulkification, fault handling, limits, testing. \"My flow\" belongs here even when salesforce-apex also names the limit. Nightly scheduling without naming code defaults here; apex takes it when code/class/Apex is named. Flow-vs-Apex choice before anything is built: admin/process-automation-selection. Use when the request mentions Flow, Flow Builder, record-triggered flo...Votes: 0GitHub stars: 15
- Salesforce IntegrationRouter for the 61 SfSkills `integration` skill packages. INBOUND integration and the API surface itself: the Salesforce REST and SOAP APIs, Bulk API 2.0 jobs, Platform Events, CDC, Pub/Sub, Named Credentials and middleware. For calling OUT to someone else's API from Apex, use salesforce-apex instead. Use when the request mentions integration, Salesforce REST API, composite API, SOAP API, Bulk API 2.0 job, Platform Event, Change Data Capture, Pub/Sub, inbound webhook, Named Credential, OAuth, ...Votes: 0GitHub stars: 15
- Salesforce LwcRouter for the 83 SfSkills `lwc` skill packages. Lightning Web Components: reactivity, wire adapters, component communication, accessibility, performance, security and Jest testing. Use when the request mentions LWC, Lightning Web Component, wire, @api, @track, lightning-record-form, shadow DOM, Jest, Lightning Message Service, Aura migration, Lightning page. Finds and opens the exact skill package to read; it does not contain the guidance itself.Votes: 0GitHub stars: 15
- Salesforce OmnistudioRouter for the 34 SfSkills `omnistudio` skill packages. OmniStudio: OmniScripts, FlexCards, DataRaptors, Integration Procedures, Business Rules Engine and DataPack deployment. Use when the request mentions OmniStudio, OmniScript, FlexCard, DataRaptor, Integration Procedure, Business Rules Engine, calculation procedure, DataPack, Vlocity. Finds and opens the exact skill package to read; it does not contain the guidance itself.Votes: 0GitHub stars: 15
- Salesforce SecurityRouter for the 49 SfSkills `security` skill packages. Platform security and compliance: org hardening, encryption, session policy, MFA, monitoring, incident response, and TROUBLESHOOTING a specific record-access denial. Designing the sharing model itself (OWD, role hierarchy, sharing rules) is salesforce-admin. Use when the request mentions security, org hardening, Shield, platform encryption, field audit trail, MFA, SSO, SAML, session policy, guest user, event monitoring, GDPR, XSS, injectio...Votes: 0GitHub stars: 15
- SalesforceEntry point for the SfSkills Salesforce library: 1,040 skill packages across 11 domains (admin, agentforce, apex, architect, data, devops, flow, integration, lwc, omnistudio, security), 70 run-time agents and 92 slash commands. Use for any Salesforce, Force.com or Lightning Platform question — Apex, SOQL, SOSL, triggers, Flow, LWC, sObject, custom field, permission set, profile, sharing rule, validation rule, deployment, sandbox, Agentforce, OmniStudio, org setup. This skill does not answer S...Votes: 0GitHub stars: 15
- CommandsYou give it a topic. It works out everything else. ``` /add-skill Data Cloud calculated insights refresh failures ``` That is the whole interface. No domain to pick, no slug to invent, no checklist to track, no "did I remember the fixture" at the end.Votes: 0GitHub stars: 15
- CommandsUse this when you know a skill is missing but don't want to build it yourself. Takes 4 questions, checks existing coverage, and adds a TODO row to `MASTER_QUEUE.md`. ---Votes: 0GitHub stars: 15
- Live Green Sample SkillWhen to use this skill. Trigger keywords. What it does NOT cover.Votes: 0GitHub stars: 15
- Live Green Sample SkillWhen to use this skill. Trigger keywords. What it does NOT cover.Votes: 0GitHub stars: 15
- Live Green Sample SkillWhen to use this skill. Trigger keywords. What it does NOT cover.Votes: 0GitHub stars: 15
- Live Green Sample SkillWhen to use this skill. Trigger keywords. What it does NOT cover.Votes: 0GitHub stars: 15