Soql Lib Query Builder
beyond-the-cloud-dev/soql-lib
Builds Salesforce SOQL queries using the SOQL Lib fluent builder API (SOQL.cls).
Apply a Salesforce sandbox post-copy automation JSON config against a target org.
$ npx skills add forcedotcom/sf-skills --skill automation-sandbox-post-copy-configure -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install forcedotcom/sf-skills automation-sandbox-post-copy-configure --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/automation-sandbox-post-copy-configure .claude/skills/automation-sandbox-post-copy-configure && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "automation-sandbox-post-copy-configure" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/automation-sandbox-post-copy-configure into .claude/skills/automation-sandbox-post-copy-configure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "automation-sandbox-post-copy-configure", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/forcedotcom/sf-skills/tree/main/skills/automation-sandbox-post-copy-configureType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add forcedotcom/sf-skills --skill automation-sandbox-post-copy-configure -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install forcedotcom/sf-skills automation-sandbox-post-copy-configure --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/automation-sandbox-post-copy-configure .agents/skills/automation-sandbox-post-copy-configure && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "automation-sandbox-post-copy-configure" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/automation-sandbox-post-copy-configure into .agents/skills/automation-sandbox-post-copy-configure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "automation-sandbox-post-copy-configure", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forcedotcom/sf-skills --skill automation-sandbox-post-copy-configure -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install forcedotcom/sf-skills automation-sandbox-post-copy-configure --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/automation-sandbox-post-copy-configure .cursor/skills/automation-sandbox-post-copy-configure && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "automation-sandbox-post-copy-configure" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/automation-sandbox-post-copy-configure into .cursor/skills/automation-sandbox-post-copy-configure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "automation-sandbox-post-copy-configure", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/forcedotcom/sf-skills.git --path skills/automation-sandbox-post-copy-configure--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add forcedotcom/sf-skills --skill automation-sandbox-post-copy-configure -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install forcedotcom/sf-skills automation-sandbox-post-copy-configure --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/automation-sandbox-post-copy-configure .gemini/skills/automation-sandbox-post-copy-configure && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "automation-sandbox-post-copy-configure" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/automation-sandbox-post-copy-configure into .gemini/skills/automation-sandbox-post-copy-configure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "automation-sandbox-post-copy-configure", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install forcedotcom/sf-skills automation-sandbox-post-copy-configureInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add forcedotcom/sf-skills --skill automation-sandbox-post-copy-configure -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/automation-sandbox-post-copy-configure .github/skills/automation-sandbox-post-copy-configure && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "automation-sandbox-post-copy-configure" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/automation-sandbox-post-copy-configure into .github/skills/automation-sandbox-post-copy-configure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "automation-sandbox-post-copy-configure", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forcedotcom/sf-skills --skill automation-sandbox-post-copy-configure -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install forcedotcom/sf-skills automation-sandbox-post-copy-configure --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/automation-sandbox-post-copy-configure .opencode/skills/automation-sandbox-post-copy-configure && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "automation-sandbox-post-copy-configure" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/automation-sandbox-post-copy-configure into .opencode/skills/automation-sandbox-post-copy-configure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "automation-sandbox-post-copy-configure", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
automation-sandbox-post-copy-configureApply a Salesforce sandbox post-copy automation JSON config against a target org.
Automation Sandbox Post Copy Configure is an agent skill from forcedotcom/sf-skills. Apply a Salesforce sandbox post-copy automation JSON config against a target org. For each entry, the skill derives the correct Tooling API sobject from the entry's ConfigurationName, verifies the derivation via a describe probe, resolves the record Id via SOQL-over-REST, then PATCHes the record via the compound Metadata field using sf api request rest. ScheduledApex entries run anonymous Apex System.schedule(...) via sf apex run (because CronTrigger is read-only) and verify via a CronTrigger SOQL read-back. Use…
Its SKILL.md is about 5.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 20 other files, including scripts, reference files and assets (for example `assets/api_request_templates.json`, `examples/sample_config_input.json` and `examples/sample_execution_summary.md`).
It sits in Sales & Support, covering CRM management and Operations and SOPs. It works with Salesforce. The repository describes itself as: Salesforce's curated collection of agent skills for building applications. Optimized for Agentforce Vibes, compatible with all AI tools. The licence is Apache-2.0.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 4bbae5c. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
BashReadWriteFrom allowed-tools in the SKILL.md frontmatter.
Ships 6 files in scripts/ (JavaScript), which the agent can run.
Shell commands in SKILL.md call:
sfnodejqFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Automation Sandbox Post Copy Configure loads about 5.4k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 263 tokens; SKILL.md has 2,345 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Bash, Read, WriteAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from forcedotcom/sf-skills at commit 4bbae5c, republished under its Apache-2.0 licence (© forcedotcom). 2,345 words, ~5,371 tokens.
.claude/skills/automation-sandbox-post-copy-configure/SKILL.md (or your agent's skills folder). This skill also uses 16 other files; get the full folder from GitHub.Apply a Salesforce sandbox post-copy automation JSON config to a target
org. Three canonical ConfigurationName values are pinned:
OutboundMessages and RemoteSiteSettings take the compound-Metadata
PATCH route (Steps A–E); ScheduledApex takes the anonymous-Apex route
(Step F), because CronTrigger is read-only in the Tooling API. Any
other ConfigurationName is derived and describe-verified. Every A–E
entry — pinned or derived — must pass Step B (describe returns 200 with
a Metadata compound field) before any PATCH is planned; Step B does
not apply to ScheduledApex. Entries whose API cannot be verified are
surfaced in the summary and skipped — never guessed at.
Use ONLY the Bash tool to execute sf CLI commands (sf data query --use-tooling-api, sf api request rest, sf org display). Do NOT
use MCP tools like execute_soql — ignore them completely; the
compound Metadata PATCH pattern this skill requires is not available
through MCP tool wrappers. If the target org alias is not explicitly
named by the user, invoke sf commands without --target-org —
the harness has already set the CLI's default target-org. Never pass
--target-org default — default is not an alias and will fail with
NamedOrgNotFoundError.
SOQL-over-REST (sf data query --use-tooling-api ...) is treated as
an API call — same OAuth session, same authorization boundary as the
subsequent PATCH. No direct database / non-Salesforce SQL access.
Never call the org from memory. Before the first request:
./post-copy-config.json). Every entry must have all five
keys (ConfigurationName, Label, Fields, IsActive,
ExecutionOrder). If any entry is malformed, abort and surface the
file path + entry index — do not partially apply. Do not
invent entries. If the file is missing, stop and ask; never
fabricate a plan against synthetic labels.ConfigurationName in the config, run the
derivation + describe-verify step (below) before planning any
PATCH. An entry whose API cannot be verified must never appear as
a planned PATCH — it is rejected up front.If you announce "I will apply … now" without having read the config
file and run the describe-verify for every distinct
ConfigurationName, stop and do those first.
The skill carries a pinned mapping for the canonical types below, and
a derive-then-verify path for anything else. Follow these steps for
every entry, in order. Step B (describe-verify) is mandatory
regardless of whether the mapping came from the pinned table or the
derive path — its HTTP status must appear in the summary.
Pinned canonicals (authoritative — use these exactly, do NOT substitute a different sobject name):
| ConfigurationName | Tooling API sobject | Record-lookup SOQL |
|---|---|---|
OutboundMessages | WorkflowOutboundMessage | SELECT Id, FullName FROM WorkflowOutboundMessage WHERE EntityDefinition.QualifiedApiName = '<Fields.Object>' — then client-side pick the row whose FullName == '<Fields.Object>.<Label>'. SOQL cannot filter on FullName directly for this sobject. |
RemoteSiteSettings | RemoteProxy | SELECT Id, SiteName FROM RemoteProxy WHERE SiteName = '<Label>'. |
ScheduledApex | CronTrigger (read-only — Anonymous Apex route, see Step F) | See Step F — pre-flight SELECT Id FROM CronTrigger WHERE CronJobDetail.Name = '<escaped>' gate. |
For canonical entries use the pinned sobject and SOQL as-is; skip
"derive". Do not invent OutboundMessage, RemoteSiteSetting, or
MasterLabel variants — plausible-looking but wrong.
Field-name resolution (overrides + case rule + existence check) is
owned by scripts/map-metadata-key.mjs.
Non-canonical: derive a candidate (usually singular of the Metadata API type name, sometimes prefixed); Step B rules out wrong guesses. Use the generic SOQL patterns in Step C.
For each candidate, GET the describe:
sf api request rest \
"/services/data/v<apiVersion>/tooling/sobjects/<Candidate>/describe/"Accept the candidate only if both are true:
fields array contains a field named
Metadata (compound field — this is what PATCH writes through).If no candidate passes both gates, mark the entry
API_NOT_IDENTIFIED and skip. Do not guess a REST path — the
wrong path 404s in the best case and updates the wrong record in the
worst case.
For pinned canonicals: run the SOQL from the Step A table
verbatim (substituting <Label> / <Fields.Object>). Do not
substitute a different filter column such as MasterLabel — the
pinned SOQL is the tested-and-correct filter for that sobject.
For non-canonical (derived) sobjects: query the verified sobject
for the record identified by the entry's Label (and Fields.Object
when present):
# SOQL to a variable + separate jq call — avoids the most common
# shell-quoting failure in this skill.
SOQL='SELECT Id, FullName FROM <VerifiedSobject> WHERE <UniqueFilter>'
sf data query --use-tooling-api --json --query "$SOQL" \
> /tmp/entry-<Slug>-lookup.json
ID=$(jq -r '.result.records[0].Id // empty' /tmp/entry-<Slug>-lookup.json)Pick <UniqueFilter> based on the queryable fields shown in the
describe response from Step B. If the row contains a FullName field,
SOQL usually rejects a direct FullName = ... filter — filter by
whichever direct column the describe surfaces (e.g.
EntityDefinition.QualifiedApiName, DeveloperName, SiteName) and
apply the FullName match client-side (jq -r '.result.records[] | select(.FullName == "<Object>.<Label>") | .Id').
Outcomes:
NOT_FOUND (never fall back to insert).AMBIGUOUS (surface
all Ids in the summary and skip; a wrong Id is worse than no Id).Metadata is replace-in-full — omitted keys are blanked on
PATCH. Preserve every existing key from the Step D-1 GET; overlay
only the mutated keys. The summary's "planned PATCH body" (apply
and dry-run) is this full merged object — verbose or org-specific
values may render as "<preserved-from-GET>" in dry-run, but
every key must be present.
Every Step D filename must include the record <Id> from Step C
(e.g. /tmp/entry-<Id>-meta.json) — phase-parallel entries share
the working directory and would clobber a shared name.
Metadata → /tmp/entry-<Id>-meta.json.Fields.<Xxx>, run
node scripts/map-metadata-key.mjs "<ConfigurationName>" "<ConfigFieldName>" /tmp/entry-<Id>-meta.json. On
{"status":"OK","key":...} use the returned key. On
{"status":"FIELD_MAP_UNKNOWN",...} mark the entry and skip./tmp/entry-<Id>-mutation.json, merge
with jq --slurpfile m /tmp/entry-<Id>-mutation.json '. + $m[0] | {Metadata: .}' /tmp/entry-<Id>-meta.json > /tmp/entry-<Id>-patch.json (preserves JSON types), PATCH with
-b @/tmp/entry-<Id>-patch.json, capture the response body to
/tmp/entry-<Id>-response.json. Full bash in
references/api_endpoints.md §Step D. Never use --arg
(stringifies booleans/numbers, breaks on special chars). Wrap
the PATCH in for attempt in 1 2; do <cmd> && break; done —
retry once on shell/jq quoting failure (non-zero exit before
the HTTP call goes out).node scripts/classify-patch-result.mjs "<httpCode>" /tmp/entry-<Id>-response.json. Exit 0 → SUCCESS;
exit 2 → FAILED (parsed error on stdout). 204 with a non-empty
body is FAILED.Re-read the record to confirm the PATCH stuck:
Metadata-writable fields are not), a SELECT
by Id is enough..Metadata.If the read-back value doesn't match the requested value, record
FAILED_VERIFY — the PATCH returned 204 but the effect is not
visible (usually a naming or permission issue).
ScheduledApex entries target the read-only CronTrigger sobject —
Steps A–E do not apply. Read references/scheduled_apex_path.md
before executing — it owns the full F-1 → F-4 recipe (pre-flight
AMBIGUOUS gate, snippet build, sf apex run, verify, dry-run).
IsActive: true → apply the PATCH as described in Steps A–E.IsActive: false → do not PATCH. Record SKIPPED_INACTIVE
for the entry and add a bullet under Follow-ups in the summary
file listing the entry's ConfigurationName + Label so the
customer notices that a config-declared inactive record was left
untouched on the target org.Rationale: IsActive: false means "not active in this sandbox",
not "deactivate the existing record". Silently deactivating a live
integration is a much bigger blast radius than leaving it alone.
Single Markdown summary written to ./post-copy-<mode>-summary.md
(mode is dry-run or apply) AND printed to the user. No JSON
side-files (plan/phases.json, requests/*.request.json, etc.) —
inline every planned/actual request in the Markdown.
Phase enumeration is script-owned. Run node scripts/plan-phases.mjs <config.json> and consume its phases[] verbatim — each entry carries
ordinal (1-indexed for headings) and executionOrder (raw, for
(ExecutionOrder = <raw>)); sparse values collapse; IsActive:false
entries are pre-marked SKIP_INACTIVE. See
references/execution_phasing.md for the worked example.
Target-org resolution is script-owned. Run node scripts/resolve-target-org.mjs; substitute the returned .alias into
the header. Never emit <env:SF_TARGET_ORG> or $SF_TARGET_ORG
verbatim.
For dry-run entries the HTTP column is —. End the summary with:
No PATCH requests were issued. To apply, re-run without the dry-run flag.
# Post-Copy Configure Run — <N> entries <planned|applied> against `<alias>`
Config file: `<path>`
Target org: `<alias>`
Mode: <dry-run|apply>
## Phase <ExecutionOrder> — <count> entr(y|ies)
Planned request:
- Method: `PATCH`
- Path: `/services/data/v<apiVersion>/tooling/sobjects/<VerifiedSobject>/<Id>`
- Body: `<JSON — the FULL merged Metadata object: every existing key from the Step D-1 GET, overlaid with the mutated keys from the config. Preserved keys with verbose or org-specific values may appear as "<preserved-from-GET>" placeholder strings, but every key must be present. NEVER emit a minimal body containing only the mutated keys.>`
| ConfigurationName | Label | Object | Sobject | Describe | Outcome | HTTP |
|-------------------|-------|--------|---------|----------|---------|------|
| <name> | <lbl> | <obj> | <VerifiedSobject> | <200 or 404> | <outcome> | <code> |
## Totals
| Outcome | Count |
|---------|-------|
| <state> | <n> |
## Follow-ups
- <bullet per SKIPPED_INACTIVE / API_NOT_IDENTIFIED / AMBIGUOUS / FIELD_MAP_UNKNOWN / NOT_FOUND entry>Column semantics: Object = the entry's Fields.Object if present,
— otherwise. Sobject = the Step A resolved sobject. Describe =
the Step B describe HTTP status (200 for verified, 404 for
API_NOT_IDENTIFIED) — mandatory so skipped Step Bs are visible at a
glance. Outcome vocabulary: SUCCESS, NOT_FOUND, AMBIGUOUS,
API_NOT_IDENTIFIED, FIELD_MAP_UNKNOWN, FAILED, FAILED_VERIFY,
SKIPPED_INACTIVE, SKIPPED, DRY_RUN, DELETE_NOT_SUPPORTED,
NOT_ATTEMPTED.
Scripts are internal. Do not inline raw node scripts/… stdout
or "I ran node …" narration into the summary or the printed response —
consume the JSON, use the returned values, render the exact shape above.
automation-sandbox-post-copy-config-generate), grouping entries
into ExecutionOrder phases, deriving+verifying the Tooling API
sobject for each entry, resolving Ids via SOQL-over-REST, PATCHing
via compound Metadata, and reporting per-entry outcomes.automation-sandbox-post-copy-config-generate); deploying
metadata XML; running the Async Task Framework (ATF) orchestrator
itself (that is the platform-side Java implementation); inventing
API paths for ConfigurationName values whose describe probe
fails (surface as API_NOT_IDENTIFIED and stop).Every API call is against a live org. Treat this skill as a mutation
tool: prefer --dry-run first, confirm the target org alias, and
never silently retry a failed entry against a different endpoint.
Gather or infer before applying:
automation-sandbox-post-copy-config-generate (default:
./post-copy-config.json in the current directory). If the file
does not exist, stop and ask.sf CLI alias or username of
the target sandbox. Never assume the default org — always confirm.
If the user has not supplied one, list available orgs with sf org list --json and ask which to use.false): reads ALLOWED, writes
FORBIDDEN — not "no network calls". Still run every read (Step B
describe GET, Step C SOQL, Step D-1 record GET); the plan's
would-be PATCH body is only accurate against the real Metadata block.
The ONLY skipped calls are Step D-3 (PATCH) and Step E (verify).
Never fabricate current Metadata or invent keys. On a read failure
(401, 404, NamedOrgNotFoundError), surface and stop — never fall
back to a from-memory plan. Prefer dry-run on the first pass.true): true = failing
entries don't abort the phase (failure reported in the summary);
false = abort mid-phase.If the user supplies a clear config path and target alias, proceed without further questions.
Every step executes real sf CLI commands via Bash. Do NOT narrate the
plan without running the commands — this skill mutates the target org.
Read and validate the config JSON — load the file with the
Read tool. Every entry must be a JSON object with the five
top-level keys (ConfigurationName, Label, Fields,
IsActive, ExecutionOrder). Malformed entries are a hard stop.
Resolve the target org and API version — run
sf org display --json. Parse the JSON to confirm the alias
resolves and to capture result.apiVersion (e.g. 62.0). Do not
print the raw JSON — it contains the access token.
Plan phases — run node scripts/plan-phases.mjs <config.json>
and iterate its phases[] output. See
references/execution_phasing.md for the concurrency cap.
Per-entry describe-verify pass — for each distinct
ConfigurationName NOT equal to ScheduledApex, run Step A +
Step B once and cache the verified sobject. Any ConfigurationName
failing Step B marks every entry with that name as
API_NOT_IDENTIFIED. ScheduledApex skips describe-verify — it
uses the Anonymous Apex route (Step F), not compound-Metadata
PATCH.
Per-entry apply pass — for each entry inside each phase:
SKIP_INACTIVE pre-marked by plan-phases → record
SKIPPED_INACTIVE, add a Follow-ups bullet, continue.ScheduledApex → Step F (F-1 pre-flight, F-2 build, F-3 run,
F-4 verify). Dry-run: run F-1 + F-2 only; record DRY_RUN.DRY_RUN.Between phases — wait for every entry in the current phase to complete before starting the next.
Write the summary file to disk — the final deliverable is a
Markdown file at ./post-copy-<mode>-summary.md, following the
shape in the "Canonical output shape" section. Also print it to
the user. Never write access tokens or full sf org display
output. If a URL contains embedded credentials, mask them in the
summary (https://user:***@host/...); the actual PATCH body
carries the verbatim URL.
Load-bearing invariants (never insert; describe-gate every
ConfigurationName; compound Metadata PATCH preserves the full
existing block; IsActive: false → SKIPPED_INACTIVE; never print
raw access tokens; cap intra-phase concurrency at 5) and the
canonical response for each runtime failure (401 mid-run, 429,
credential-bearing URLs, Fields.Action = "Delete", describe 404,
zero/many SOQL rows) live in references/rules_gotchas.md. Read
that file before deviating from the Step A–E procedure.
| Need | Delegate to |
|---|---|
| Turn a customer SOP into the JSON config this skill consumes | automation-sandbox-post-copy-config-generate |
| Deploy metadata XML outside the compound-Metadata Tooling pattern | Matching generating-* skill + a metadata deploy flow |
| Create new records that do not yet exist on the target org | platform-metadata-deploy |
| Assign permission sets required for the API calls | dx-org-permission-set-assign |
| File | When to read |
|---|---|
references/api_endpoints.md | Steps A–E — full generic recipe with OBM / RSS worked examples and the camelCase-field convention |
references/scheduled_apex_path.md | Step F — anonymous Apex route for ScheduledApex entries |
references/execution_phasing.md | Step 3 (workflow) — phase-grouping model behind scripts/plan-phases.mjs |
references/authentication.md | Step 2 — session check + how to handle 401 mid-run |
references/rules_gotchas.md | Before deviating from Step A–E — invariants and runtime-failure responses |
scripts/plan-phases.mjs | Step 3 — deterministic phase planner |
scripts/map-metadata-key.mjs | Step D-2 — deterministic Metadata-key resolver |
scripts/classify-patch-result.mjs | Step D-4 — deterministic HTTP-outcome classifier |
scripts/resolve-target-org.mjs | Canonical output shape — target-org alias resolver |
scripts/build-scheduled-apex.mjs | Step F-2 — anonymous-Apex snippet builder |
scripts/soql-escape-job-name.mjs | Step F-1/F-4 — SOQL-escape JobName |
assets/api_request_templates.json | Steps A–E — generic describe / lookup / GET+PATCH template |
assets/scheduled_apex_template.apex | Step F-2 — anonymous Apex template with {{JOB_NAME}} / {{CRON_EXPRESSION}} / {{APEX_CLASS_NAME}} placeholders |
examples/sample_config_input.json | Step 1 — shape of the config JSON this skill consumes |
examples/sample_scheduled_apex_config.json | Step 1 — shape of a ScheduledApex config entry |
examples/sample_execution_summary.md | Step 7 — shape of the summary report shown to the user |
© forcedotcom, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 16 other files (scripts, references, assets) in skills/automation-sandbox-post-copy-configure of forcedotcom/sf-skills.
Open the folder on GitHubat commit 4bbae5c
Automation Sandbox Post Copy Configure next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Automation Sandbox Post Copy Configure this skillforcedotcom/sf-skills | 1.1k | — | ~5.4k | Automated safety check: Notes | Apache-2.0 | |
| Soql Lib Query Builderbeyond-the-cloud-dev/soql-lib | 154 | — | ~4.3k | Automated safety check: Pass | MIT | |
| Sf DatacloudJaganpro/sf-skills | 424 | — | ~2.7k | Automated safety check: Pass | MIT | |
| Soql Lib Selectorbeyond-the-cloud-dev/soql-lib | 154 | — | ~2k | Automated safety check: Pass | MIT | |
| Dev SetupPortwood-Global-Solutions/Portwood | 126 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | |
| Sf FlowJaganpro/sf-skills | 424 | — | ~1.8k | Automated safety check: Pass | MIT |
beyond-the-cloud-dev/soql-lib
Builds Salesforce SOQL queries using the SOQL Lib fluent builder API (SOQL.cls).
Jaganpro/sf-skills
Salesforce Data Cloud product orchestrator for connect→prepare→harmonize→segment→act workflows.
beyond-the-cloud-dev/soql-lib
Creates Salesforce Apex selector classes using the SOQL Lib selector pattern.
Portwood-Global-Solutions/Portwood
Get from a fresh clone of Portwood to a working, fully-tested Salesforce org.
Jaganpro/sf-skills
Creates and validates Salesforce Flows with 110-point scoring.
gmapsscraper/google-maps-agent-skills
Export Google Maps business data to CSV, JSON, or CRM format (HubSpot, Pipedrive, Salesforce).
forcedotcom/sf-skills
Declared architecture snapshot for one Agentforce agent: planner, topics, actions, flows, Apex, prompt templates, and NGA plugins.
forcedotcom/sf-skills
Data Cloud 360° view of a single Agentforce session. An agent skill from forcedotcom/sf-skills.
forcedotcom/sf-skills
Apply a Salesforce sandbox post-copy automation JSON config against a target org.
forcedotcom/sf-skills
Apply SLDS-compliant UI using the correct blueprints, styling hooks, utility classes, and icons.
forcedotcom/sf-skills
Lightning Web Components with PICKLES methodology and 165-point scoring.
forcedotcom/sf-skills
Migrate legacy Salesforce UI stacks onto modern LWC — Aura → LWC conversion completeness verification and Lightning Out Beta → Lightning Out 2.0 host-page migration.
Works with
Categories
Apply a Salesforce sandbox post-copy automation JSON config against a target org. Automation Sandbox Post Copy Configure is an agent skill from forcedotcom/sf-skills. Apply a Salesforce sandbox post-copy automation JSON config against a target org.
Automation Sandbox Post Copy Configure fits situations like: the user asks to apply; preview a post-copy; post-refresh config file (e.g; phrases: apply post-copy config.
Run `npx skills add forcedotcom/sf-skills --skill automation-sandbox-post-copy-configure -a claude-code`. Or copy the skill folder (skills/automation-sandbox-post-copy-configure in forcedotcom/sf-skills) into .claude/skills/automation-sandbox-post-copy-configure in your project. Claude Code loads it when a task matches its description.
Run `npx skills add forcedotcom/sf-skills --skill automation-sandbox-post-copy-configure -a codex`. Or copy the skill folder (skills/automation-sandbox-post-copy-configure in forcedotcom/sf-skills) into .agents/skills/automation-sandbox-post-copy-configure in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forcedotcom/sf-skills --skill automation-sandbox-post-copy-configure -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/automation-sandbox-post-copy-configure, .gemini/skills/automation-sandbox-post-copy-configure, .github/skills/automation-sandbox-post-copy-configure and .opencode/skills/automation-sandbox-post-copy-configure in your project.
Going by SKILL.md and its folder, Automation Sandbox Post Copy Configure needs JavaScript for the scripts in its folder and the command-line tools its instructions call (sf, node and jq). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Bash, Read, Write.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Automation Sandbox Post Copy Configure is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.4k tokens (SKILL.md is roughly 21k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.8k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Automation Sandbox Post Copy Configure: Soql Lib Query Builder (beyond-the-cloud-dev/soql-lib, 154 stars), Sf Datacloud (Jaganpro/sf-skills, 424 stars), Soql Lib Selector (beyond-the-cloud-dev/soql-lib, 154 stars) and Dev Setup (Portwood-Global-Solutions/Portwood, 126 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
forcedotcom (a GitHub organization) maintains it in forcedotcom/sf-skills, which has 1,067 GitHub stars. The repository holds 252 skills in this directory. The repository was last updated on October 9, 2026.
Source: forcedotcom/sf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.