Soql Lib Query Builder
beyond-the-cloud-dev/soql-lib
Builds Salesforce SOQL queries using the SOQL Lib fluent builder API (SOQL.cls).
Run an ApexGuru performance scan on a Salesforce Apex project via the ApexGuru SFAP Scan API.
$ npx skills add forcedotcom/sf-skills --skill dx-apexguru-scan -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install forcedotcom/sf-skills dx-apexguru-scan --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dx-apexguru-scan .claude/skills/dx-apexguru-scan && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dx-apexguru-scan" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/dx-apexguru-scan into .claude/skills/dx-apexguru-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dx-apexguru-scan", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/forcedotcom/sf-skills/tree/main/skills/dx-apexguru-scanType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add forcedotcom/sf-skills --skill dx-apexguru-scan -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install forcedotcom/sf-skills dx-apexguru-scan --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/dx-apexguru-scan .agents/skills/dx-apexguru-scan && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dx-apexguru-scan" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/dx-apexguru-scan into .agents/skills/dx-apexguru-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dx-apexguru-scan", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forcedotcom/sf-skills --skill dx-apexguru-scan -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install forcedotcom/sf-skills dx-apexguru-scan --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/dx-apexguru-scan .cursor/skills/dx-apexguru-scan && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dx-apexguru-scan" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/dx-apexguru-scan into .cursor/skills/dx-apexguru-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dx-apexguru-scan", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/forcedotcom/sf-skills.git --path skills/dx-apexguru-scan--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add forcedotcom/sf-skills --skill dx-apexguru-scan -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install forcedotcom/sf-skills dx-apexguru-scan --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/dx-apexguru-scan .gemini/skills/dx-apexguru-scan && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dx-apexguru-scan" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/dx-apexguru-scan into .gemini/skills/dx-apexguru-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dx-apexguru-scan", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install forcedotcom/sf-skills dx-apexguru-scanInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add forcedotcom/sf-skills --skill dx-apexguru-scan -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/dx-apexguru-scan .github/skills/dx-apexguru-scan && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dx-apexguru-scan" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/dx-apexguru-scan into .github/skills/dx-apexguru-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dx-apexguru-scan", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forcedotcom/sf-skills --skill dx-apexguru-scan -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install forcedotcom/sf-skills dx-apexguru-scan --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/dx-apexguru-scan .opencode/skills/dx-apexguru-scan && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dx-apexguru-scan" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/dx-apexguru-scan into .opencode/skills/dx-apexguru-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dx-apexguru-scan", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dx-apexguru-scanRun an ApexGuru performance scan on a Salesforce Apex project via the ApexGuru SFAP Scan API.
Dx Apexguru Scan is an agent skill from forcedotcom/sf-skills. Run an ApexGuru performance scan on a Salesforce Apex project via the ApexGuru SFAP Scan API. Zips the project's Apex (any layout), submits it, polls to completion, decodes the base64 report, and presents performance antipattern violations (SOQL in loop, DML in loop, Schema.getGlobalDescribe(), SOQL without WHERE/LIMIT, unused SOQL fields) grouped by rule with severity, file:line, and suggested fixes — clearly attributed as 'Static only' or 'Production insights'. TRIGGER when the user says 'run ApexGuru'…
Its SKILL.md is about 5.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 17 other files, including scripts and reference files (for example `examples/README.md`, `examples/sample-decoded-summary.json` and `examples/sample-full-no-runtime-response.json`).
It sits in Sales & Support, covering Static analysis and SAST, CRM management and Security review. It works with Salesforce. The repository describes itself as: Salesforce's curated collection of agent skills for building applications. Optimized for Agentforce Vibes, compatible with all AI tools. The licence is Apache-2.0.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 4bbae5c. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadBash(bash)Bash(node)Bash(curl)Bash(zip)Bash(unzip)Bash(jq)Bash(sf)Bash(date)WriteFrom allowed-tools in the SKILL.md frontmatter.
Ships 6 files in scripts/ (Shell and JavaScript), which the agent can run.
Shell commands in SKILL.md call:
bashnodejqcurlsfFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
api.salesforce.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
APEXGURU_SFAP_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dx Apexguru Scan loads about 5.1k tokens when it runs, and up to ~8.9k if it reads all its reference files. Until then it costs about 216 tokens; SKILL.md has 2,165 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from forcedotcom/sf-skills at commit 4bbae5c, republished under its Apache-2.0 licence (© forcedotcom). 2,165 words, ~5,101 tokens.
.claude/skills/dx-apexguru-scan/SKILL.md (or your agent's skills folder). This skill also uses 14 other files; get the full folder from GitHub.Every step — token resolution, zipping, API calls, and report decoding — MUST go
through the bundled scripts in <skill_dir>/scripts/. No exceptions.
# WRONG: hand-rolled curl to the API
curl -X POST https://api.salesforce.com/... -F file=@x.zip
# WRONG: inline base64 + jq to read the report
cat raw.json | jq -r .report | base64 -d | jq '.[]'
# WRONG: reading the raw result file directly (report is a large base64 blob)
Read tool → apexguru-raw-*.json
# WRONG: inline node/python to parse violations
node -e "const r = require('./raw.json'); ..."# PREFERRED — one command runs all three steps (package → submit+poll →
# decode+present) and prints the ready-to-show report as its final stdout.
# Use this for every initial scan: it cannot be left half-finished.
bash "<skill_dir>/scripts/scan.sh" "<project-root>"
# Optionally persist the presented markdown to a file as well:
bash "<skill_dir>/scripts/scan.sh" "<project-root>" --out ./apexguru-report.mdThe three underlying scripts still exist and scan.sh calls them in order.
Invoke them individually only for drill-downs on an already-scanned result
(Step 5), or when you deliberately need to inspect an intermediate artifact:
# Equivalent manual chain (scan.sh runs exactly these, in this order):
bash "<skill_dir>/scripts/build-zip.sh" "<project-root>" "./apexguru-<TS>.zip"
bash "<skill_dir>/scripts/run-scan.sh" "./apexguru-<TS>.zip" "./apexguru-raw-<TS>.json"
node "<skill_dir>/scripts/decode-report.js" "./apexguru-raw-<TS>.json" --present
# Drill into a subset WITHOUT re-scanning (reuse the raw file scan.sh left, or
# pass --raw to scan.sh to keep it at a known path):
node "<skill_dir>/scripts/decode-report.js" "./apexguru-raw-<TS>.json" --rule SOQL_IN_LOOP --full
node "<skill_dir>/scripts/decode-report.js" "./apexguru-raw-<TS>.json" --group file --top 5<skill_dir> is the absolute path to the directory containing this SKILL.md.
Never use ./scripts/ — that resolves against the user's CWD, not the skill dir.
Any filter/rank/group question ("which file has the most issues?", "show only
SOQL-in-loop", "break down by severity") is answered by re-running
decode-report.js with flags against the same raw result file — never re-scan,
never parse the JSON by hand.
--present output verbatim — never condense itdecode-report.js --present (Step 4) already produces the final, ready-to-show
markdown: severity legend, one detail card per violation (message, code, fix,
resource link), and a closing summary table. That stdout is the response.
Print it to the user exactly as printed — do not rewrite it into a shorter
table, do not drop the per-issue cards down to just the summary table, and do
not wait for the user to ask "explain a violation" before including
message/fix/resource. Condensing it defeats the entire point of --present.
The attribution is already in that stdout — the summary line is the exact output that states the mode (e.g. "ApexGuru (static analysis) is active. To unlock runtime intelligence…"). Do NOT prepend or append your own attribution sentence (no "Attribution: analysisMode: static…", no naming the org, no restating "static-only findings"). The script's line is the complete, approved wording; adding your own makes the output non-deterministic and off-message.
Top Issues (worst first)
# Severity Rule Method Line
1 Major UsingTheTestMethodKeyword legacy... 136
...
Key Antipatterns Detected:
- SOQL/DML in loops (3 violations)(a hand-built summary that drops every message/code/fix — even for violations that had one)
Attribution: analysisMode: static — source-only analysis. The scanned org
(ag-skills-org) is not onboarded to ApexGuru's full runtime metrics, so
these are static-only findings.(an agent-authored attribution line prepended to the report — the script's own summary line already states the mode; this duplicate is non-deterministic and names an org the script never had access to)
Paste the full stdout from decode-report.js --present — every ### Issue N
card and the closing ## Summary table — unedited, in one response.
ApexGuru detects performance antipatterns in Apex (SOQL/DML in loops,
Schema.getGlobalDescribe(), SOQL without WHERE/LIMIT, unused SOQL fields).
This skill drives the ApexGuru SFAP Scan API: it packages the user's Apex
(every .cls/.trigger under the project root, any layout) into a zip, submits
it, polls until the scan finishes, decodes the base64-encoded report, and
presents violations grouped by rule with severity, file:line, and suggested
fixes.
Attribution is mandatory. The API returns analysisMode:
static → source-only analysis → label results "Static only".full → enriched with runtime metrics from an org onboarded to ApexGuru →
label results "Production insights".decode-report.js --present already renders this attribution into its summary
line and title ("Static only" / "Production insights") — that satisfies the
mandatory-attribution requirement. Print that line as the exact output; do not
author your own attribution sentence or name the org. If the user expected
full but got static, the script's static-mode line already explains the org
is not onboarded — point them to it rather than restating it (see error handling).
In scope: zipping a project's Apex, submitting/polling the scan, decoding + presenting violations, filtering/grouping existing results, troubleshooting API errors.
Out of scope: general static analysis / security / lint (→ dx-code-analyzer-run,
which lists ApexGuru as an engine), applying fixes to code, onboarding an org to
ApexGuru, minting SFAP tokens.
sf CLI org (sf org login web ...). resolve-token.sh
derives the SFAP JWT from it via <instanceUrl>/ide/auth — this is the normal
IDE-session path. Alternatively, set APEXGURU_SFAP_TOKEN / APEXGURU_SFAP_TOKEN_FILE
to supply a JWT directly (CI/headless). The org is derived from the token's tnk
claim — no org id is passed. Pass --org <alias> to pick a specific org.
See <skill_dir>/references/authentication.md. If no token can be resolved, the
script returns a clear error with a hint.sf, bash, curl, zip, jq, node on PATH (standard on macOS/Linux dev boxes).force-app/ subtree, or any
folder with .cls/.trigger files. build-zip.sh collects all Apex beneath
it regardless of layout; the API walks the whole archive.The project root is any folder that contains Apex somewhere beneath it
(usually an sfdx project root next to sfdx-project.json, but a force-app/
subtree or a loose folder of .cls files works too). If the user gave a path,
use it; otherwise use the current working directory. build-zip.sh collects
every .cls/.trigger under it (any layout) and fails clearly if none exists.
TS=$(date +%Y%m%d-%H%M%S)
bash "<skill_dir>/scripts/build-zip.sh" "<project-root>" "./apexguru-${TS}.zip"Output JSON gives zip, bytes, humanSize, apexFileCount, scanRoot. The script enforces
the 200MB compressed limit and fails fast if exceeded. On error (error/hint
fields), relay the hint and stop.
bash "<skill_dir>/scripts/run-scan.sh" "./apexguru-${TS}.zip" "./apexguru-raw-${TS}.json"--fast if the user wants a quicker/cheaper run (skips LLM-heavy fix
generation).tnk claim: a prod org hits api.salesforce.com, and an
internal stage/dev org hits stage./dev.api.salesforce.com. Customers
authenticate a prod org, so they always hit prod; no extra flags or config.--org <alias> picks which authenticated sf org the JWT is derived from
(omit to use the CLI's default org).QUEUED → RUNNING → SUCCEEDED) streams to stderr; the script polls
~every 15s. Default ceiling is 10 min (--max-polls, --interval to adjust).apexguru-raw-${TS}.json. On failure, stdout is {error, httpStatus, status, hint} —
relay the hint. For status-code specifics see <skill_dir>/references/error-handling.md.node "<skill_dir>/scripts/decode-report.js" "./apexguru-raw-${TS}.json" --present--present is the default way to decode for presentation: it implies --full
(no silent caps) and prints ready-to-show markdown directly — a severity
legend (Minor / Major / Critical, plus a Tip marker when analysisMode: full
enriches severity from production metrics), one ### Issue N card per
violation (message, current code, suggested fix, help-doc link) for the
non-hotspot rules — capped at --top (default 10) worst-first, with the cap
stated in the heading — and a closing ## Summary table listing every
violation regardless of the card cap. ExpensiveMethods (a per-method
CPU-hotspot ranking from full mode, not a line-level antipattern) is
collapsed into its own ranked "CPU Hotspots" table instead of repeating a
near-identical card per method. Print this output to the user verbatim —
present immediately — do not pause to ask, and do not re-summarize it into
a shorter table.
For Step 5 drill-downs (filtering/grouping an existing result), the bare
(non---present) JSON form is fine — see the reading rules below, which apply
whenever you run the script without --present.
DO NOT: invent script code, use bare ./scripts/... paths, decode base64
inline, jq the report field, or Read the raw file directly.
--present) decode-report.js outputThe command prints one JSON object to stdout. Read it field by field before presenting anything — do not eyeball a partial view as complete:
truncated first, before anything else. If true, groups was
capped to the top --top (default 10) rules, each group's sample was capped
to 3 items, and topViolations was capped to --top items. Never present a
truncated:true result as the full picture. Re-run the same command with
--full appended and use that output instead. Only skip this if the user
explicitly asked for a quick/partial look.analysisMode/attribution — static/"Static
only" or full/"Production insights". This is mandatory on every response,
per "Attribution is mandatory" above.serverViolationBreakdown is the raw API's internal rule-code tally
(e.g. SOQL_IN_LOOP_1HOP, GGD) — it's a sanity-check total (sums to
violationCount), not a display name. Never show these codes to the user;
use the human-readable groups[].key names instead (e.g.
SoqlInALoopOneHop, SchemaGetGlobalDescribeNotEfficient).severityCounts (top-level) is the severity distribution across ALL
violations — use it for the summary table. Each groups[] entry has its own
severityCounts scoped to just that rule.groups, one row per entry:
key → Rule, count → Count, severityCounts → Severity, and one
sample[0] (or items[0] when --full) → Example (file:line).topViolations — already sorted
worst-severity-first. Use rule, severity, file:line, and the first
entry of fixes (if non-empty) as Suggested Fix. If fixes is empty, omit
that column's value rather than inventing a fix.message (plain-
language why) and resources[0] (Help Doc URL) verbatim — both exist on
every violation object but are intentionally left out of the summary tables
in step 5/6 to keep those scannable. Fall back to
references/violation-catalog.md only if message is empty.fixes being [] is expected, not an error — the API's suggestions
field (fix code) isn't populated for every rule (notably ExpensiveMethods,
a CPU ranking with no single-line fix); don't say "no fix available", just
omit the column.--full, each group also carries an items array (every violation for
that rule, not just the 3-item sample) — use items instead of sample
when the user wants the complete list for one rule ("show me all the SOQL
unused-fields ones").--present)--present (the default, per Step 4 above) already renders the full
severity-legend + issue-cards + summary-table output described in the
"Instructions for reading bare output" section — just print its stdout
verbatim. Only build a table by hand from bare JSON if --present genuinely
can't be used (e.g. scripting/CI context with no markdown renderer):
Filling the <Static only | Production insights> title placeholder: derive
the label from the attribution field (not analysisMode alone) — it already
encodes the three states:
analysisMode: full with runtime metrics) —
enriched with production runtime metrics.analysisMode: full (no runtime metrics) — org is
onboarded, but there's no runtime data for this code yet; generate a runtime
report in Scale Center.analysisMode: static — source-only. Onboard the org to
ApexGuru for production insights.The fenced block below is the literal rendered output — substitute the real values and print it; do not emit any of the guidance above:
## ApexGuru Scan Complete — <Static only | Production insights>
**Found X performance violations** across Y files.
| Severity | Count |
|----------|-------|
| Critical (1) | X |
| High (2) | X |
| Moderate (3) | X |
### Violations by Rule
| Rule | Count | Severity | Example |
|------|-------|----------|---------|
| SOQL_IN_LOOP | 15 | High (2) | AccountService.cls:42 |
| DML_IN_LOOP | 8 | Critical (1) | AccountService.cls:60 |
| GGD | 2 | Moderate (3) | Utils.cls:12 |
### Top Issues
| # | Rule | Sev | File:Line | Suggested Fix |
|---|------|-----|-----------|---------------|
| 1 | DML_IN_LOOP | 1 | AccountService.cls:60 | Collect records; DML once after the loop |
| ... up to 10 |
Raw result: `./apexguru-raw-<TS>.json`Scale to result size: 0 → "no performance antipatterns found"; 1–10 → one
table; 11+ → severity counts + by-rule table + top 10. End with the raw result
path. Do not append your own follow-up offer (no "I can drill in without
re-scanning…", no "filter by rule / group by file / explain a violation" menu) —
--present already prints the script's "show all" footer; that is the complete,
approved closing line and adding your own makes the output non-deterministic.
Rule-catalog details: <skill_dir>/references/violation-catalog.md.
Re-run decode-report.js against the same raw file with flags:
| User says | Flags |
|---|---|
| "show only SOQL-in-loop" | --rule SOQL_IN_LOOP --full |
| "just the critical ones" | --severity 1 |
| "what's in AccountService.cls?" | --file AccountService.cls --full |
| "group by file" / "which file is worst?" | --group file --top 5 |
| "break down by severity" | --group severity |
| "show me everything" | --present (or --full for bare JSON) |
| Item | Why / Fix |
|---|---|
Run scripts with absolute <skill_dir> path | ./scripts/ resolves against the user's CWD, not the skill dir |
| Any project layout is fine | The API walks the whole archive for Apex; build-zip.sh collects every .cls/.trigger under the root, no force-app/ required |
Never decode report inline | It is a large base64 blob — always use decode-report.js |
Use --present for the initial decode | Implies --full (no silent caps) and renders ready-to-show markdown directly — severity legend, per-issue cards, closing summary table — mirroring the reference MCP tool's presentation density |
| Never re-scan to filter | Step 5 re-decodes the existing raw file instantly |
| Attribution is pre-rendered | --present already prints the mode line ("Static only" / "Production insights") — print it as the exact output; never author your own attribution sentence or name the org |
static when full expected | Org not onboarded to ApexGuru — tell the user, don't treat as an error |
| 401 / 403 / 404 / 400 | Token / org-ownership / scanId / zip issues — see references/error-handling.md |
| Foreground only, ~15s polls | Backgrounding loses progress; scans can take minutes |
| Token is a secret | resolve-token.sh never echoes it; don't print it or write it to result files |
| Not a security/lint scanner | For PMD/ESLint/security, use dx-code-analyzer-run |
Scripts (execute via bash/node with the absolute <skill_dir>/ prefix, never Read):
| File | When to use |
|---|---|
<skill_dir>/scripts/resolve-token.sh | Resolve SFAP JWT + base URL (called by run-scan.sh) |
<skill_dir>/scripts/validate-token.js | Local (no-network) JWT pre-flight: env/scope/expiry (called by resolve-token.sh) |
<skill_dir>/scripts/build-zip.sh | Step 2 — collect the project's Apex into a size-checked zip |
<skill_dir>/scripts/run-scan.sh | Step 3 — submit + poll to completion |
<skill_dir>/scripts/decode-report.js | Steps 4–5 — decode base64 report, group/filter violations |
References (read on demand):
| File | When to read |
|---|---|
references/authentication.md | Where the SFAP JWT comes from; env-var/file setup |
references/api-reference.md | Endpoint contracts, request/response shapes, limits |
references/violation-catalog.md | ApexGuru rule meanings and typical fixes |
references/error-handling.md | 400/401/403/404, FAILED, timeout, static-vs-full diagnosis |
examples/ contains a sample SUCCEEDED response and a decoded-summary sample.
© forcedotcom, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 14 other files (scripts, references) in skills/dx-apexguru-scan of forcedotcom/sf-skills.
Open the folder on GitHubat commit 4bbae5c
Dx Apexguru Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dx Apexguru Scan this skillforcedotcom/sf-skills | 1.1k | — | ~5.1k | Automated safety check: Pass | Apache-2.0 | |
| Soql Lib Query Builderbeyond-the-cloud-dev/soql-lib | 154 | — | ~4.3k | Automated safety check: Pass | MIT | |
| Sf DatacloudJaganpro/sf-skills | 424 | — | ~2.7k | Automated safety check: Pass | MIT | |
| Soql Lib Selectorbeyond-the-cloud-dev/soql-lib | 154 | — | ~2k | Automated safety check: Pass | MIT | |
| Dev SetupPortwood-Global-Solutions/Portwood | 126 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | |
| Sf FlowJaganpro/sf-skills | 424 | — | ~1.8k | Automated safety check: Pass | MIT |
beyond-the-cloud-dev/soql-lib
Builds Salesforce SOQL queries using the SOQL Lib fluent builder API (SOQL.cls).
Jaganpro/sf-skills
Salesforce Data Cloud product orchestrator for connect→prepare→harmonize→segment→act workflows.
beyond-the-cloud-dev/soql-lib
Creates Salesforce Apex selector classes using the SOQL Lib selector pattern.
Portwood-Global-Solutions/Portwood
Get from a fresh clone of Portwood to a working, fully-tested Salesforce org.
Jaganpro/sf-skills
Creates and validates Salesforce Flows with 110-point scoring.
gmapsscraper/google-maps-agent-skills
Export Google Maps business data to CSV, JSON, or CRM format (HubSpot, Pipedrive, Salesforce).
forcedotcom/sf-skills
Declared architecture snapshot for one Agentforce agent: planner, topics, actions, flows, Apex, prompt templates, and NGA plugins.
forcedotcom/sf-skills
Data Cloud 360° view of a single Agentforce session. An agent skill from forcedotcom/sf-skills.
forcedotcom/sf-skills
Apply a Salesforce sandbox post-copy automation JSON config against a target org.
forcedotcom/sf-skills
Apply a Salesforce sandbox post-copy automation JSON config against a target org.
forcedotcom/sf-skills
Apply SLDS-compliant UI using the correct blueprints, styling hooks, utility classes, and icons.
forcedotcom/sf-skills
Lightning Web Components with PICKLES methodology and 165-point scoring.
Works with
Categories
Run an ApexGuru performance scan on a Salesforce Apex project via the ApexGuru SFAP Scan API. Dx Apexguru Scan is an agent skill from forcedotcom/sf-skills. Run an ApexGuru performance scan on a Salesforce Apex project via the ApexGuru SFAP Scan API.
Dx Apexguru Scan fits situations like: the user says run ApexGuru; check Apex performance; find governor-limit / performance antipatterns; scan my Apex for performance.
Run `npx skills add forcedotcom/sf-skills --skill dx-apexguru-scan -a claude-code`. Or copy the skill folder (skills/dx-apexguru-scan in forcedotcom/sf-skills) into .claude/skills/dx-apexguru-scan in your project. Claude Code loads it when a task matches its description.
Run `npx skills add forcedotcom/sf-skills --skill dx-apexguru-scan -a codex`. Or copy the skill folder (skills/dx-apexguru-scan in forcedotcom/sf-skills) into .agents/skills/dx-apexguru-scan in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forcedotcom/sf-skills --skill dx-apexguru-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dx-apexguru-scan, .gemini/skills/dx-apexguru-scan, .github/skills/dx-apexguru-scan and .opencode/skills/dx-apexguru-scan in your project.
Going by SKILL.md and its folder, Dx Apexguru Scan needs a shell and JavaScript for the scripts in its folder, the command-line tools its instructions call (bash, node, jq, curl and sf) and credentials named APEXGURU_SFAP_TOKEN. Our summary lists: Python 3; Node.js; A Bash shell; A credential in APEXGURU_SFAP_TOKEN. Its frontmatter pre-approves these tools: Read, Bash(bash), Bash(node), Bash(curl), Bash(zip), Bash(unzip), Bash(jq), Bash(sf), Bash(date), Write.
SKILL.md names 1 domain. In commands or code: api.salesforce.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Dx Apexguru Scan is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.1k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.8k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Dx Apexguru Scan: Soql Lib Query Builder (beyond-the-cloud-dev/soql-lib, 154 stars), Sf Datacloud (Jaganpro/sf-skills, 424 stars), Soql Lib Selector (beyond-the-cloud-dev/soql-lib, 154 stars) and Dev Setup (Portwood-Global-Solutions/Portwood, 126 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
forcedotcom (a GitHub organization) maintains it in forcedotcom/sf-skills, which has 1,067 GitHub stars. The repository holds 252 skills in this directory. The repository was last updated on October 9, 2026.
Source: forcedotcom/sf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.