LobeHub Alint Rule Set Maintenance
lobehub/lobehub
Maintains LobeHub's model-backed alint rule set: writing rules, removing false positives against real code, deciding warn versus error and tracking token cost.
Run Salesforce Code Analyzer to scan code for security, performance, best practice, and code style violations.
$ npx skills add forcedotcom/sf-skills --skill dx-code-analyzer-run -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install forcedotcom/sf-skills dx-code-analyzer-run --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dx-code-analyzer-run .claude/skills/dx-code-analyzer-run && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dx-code-analyzer-run" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/dx-code-analyzer-run into .claude/skills/dx-code-analyzer-run/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dx-code-analyzer-run", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/forcedotcom/sf-skills/tree/main/skills/dx-code-analyzer-runType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add forcedotcom/sf-skills --skill dx-code-analyzer-run -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install forcedotcom/sf-skills dx-code-analyzer-run --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/dx-code-analyzer-run .agents/skills/dx-code-analyzer-run && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dx-code-analyzer-run" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/dx-code-analyzer-run into .agents/skills/dx-code-analyzer-run/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dx-code-analyzer-run", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forcedotcom/sf-skills --skill dx-code-analyzer-run -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install forcedotcom/sf-skills dx-code-analyzer-run --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/dx-code-analyzer-run .cursor/skills/dx-code-analyzer-run && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dx-code-analyzer-run" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/dx-code-analyzer-run into .cursor/skills/dx-code-analyzer-run/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dx-code-analyzer-run", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/forcedotcom/sf-skills.git --path skills/dx-code-analyzer-run--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add forcedotcom/sf-skills --skill dx-code-analyzer-run -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install forcedotcom/sf-skills dx-code-analyzer-run --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/dx-code-analyzer-run .gemini/skills/dx-code-analyzer-run && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dx-code-analyzer-run" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/dx-code-analyzer-run into .gemini/skills/dx-code-analyzer-run/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dx-code-analyzer-run", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install forcedotcom/sf-skills dx-code-analyzer-runInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add forcedotcom/sf-skills --skill dx-code-analyzer-run -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/dx-code-analyzer-run .github/skills/dx-code-analyzer-run && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dx-code-analyzer-run" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/dx-code-analyzer-run into .github/skills/dx-code-analyzer-run/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dx-code-analyzer-run", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forcedotcom/sf-skills --skill dx-code-analyzer-run -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install forcedotcom/sf-skills dx-code-analyzer-run --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/dx-code-analyzer-run .opencode/skills/dx-code-analyzer-run && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dx-code-analyzer-run" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/dx-code-analyzer-run into .opencode/skills/dx-code-analyzer-run/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dx-code-analyzer-run", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dx-code-analyzer-runRun Salesforce Code Analyzer to scan code for security, performance, best practice, and code style violations.
Dx Code Analyzer Run is an agent skill from forcedotcom/sf-skills. Run Salesforce Code Analyzer to scan code for security, performance, best practice, and code style violations. Supports all engines (PMD, ESLint, CPD, RetireJS, Flow, SFGE, ApexGuru), targets (files, folders, git diff), categories, and severities. Also handles post-scan exploration: filtering results by engine/severity/category/file, and explaining what rules mean. TRIGGER when: user says 'scan my code', 'check security issues', 'run PMD/ESLint', 'find duplicates', 'analyze Flows', 'check vulnerable libraries'…
Its SKILL.md is about 6.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 26 other files, including scripts and reference files (for example `examples/README.md`, `examples/basic-scan-output.json` and `examples/command-variations.md`).
It sits in Development, covering Linting and formatting, CRM management and Static analysis and SAST. It works with Salesforce, ESLint and Git. The repository describes itself as: Salesforce's curated collection of agent skills for building applications. Optimized for Agentforce Vibes, compatible with all AI tools. The licence is Apache-2.0.
9 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit e5164d9. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 3 files in scripts/ (JavaScript, from the files we listed), which the agent can run.
Shell commands in SKILL.md call:
nodesfgitpython3jqFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dx Code Analyzer Run loads about 6.3k tokens when it runs, and up to ~14k if it reads all its reference files. Until then it costs about 255 tokens; SKILL.md has 2,239 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from forcedotcom/sf-skills at commit e5164d9, republished under its Apache-2.0 licence (© forcedotcom). 2,239 words, ~6,272 tokens.
.claude/skills/dx-code-analyzer-run/SKILL.md (or your agent's skills folder). This skill also uses 23 other files; get the full folder from GitHub.Every interaction with Code Analyzer results MUST go through the bundled scripts in <skill_dir>/scripts/. No exceptions.
# WRONG: inline Python to parse results
python3 -c "import json; data = json.load(open('results.json'))..."
# WRONG: inline Node.js to parse results
node -e "const data = require('./results.json')..."
# WRONG: jq to filter results
cat results.json | jq '.violations[] | select(.engine=="pmd")'
# WRONG: reading the results file directly (it can be 10MB+)
Read tool → code-analyzer-results-*.jsonAlso forbidden: run_code_analyzer and any mcp__* tool — Bash only.
# Summarize scan results
node "<skill_dir>/scripts/parse-results.js" "./code-analyzer-results-TIMESTAMP.json"
# Filter/rank/query results (by engine, severity, file, rule, category)
node "<skill_dir>/scripts/query-results.js" "./code-analyzer-results-TIMESTAMP.json" --engine pmd --summary
# List/browse available rules (by engine, category, language, severity)
node "<skill_dir>/scripts/list-rules.js" "Security" --top 10
# Look up what a rule means
node "<skill_dir>/scripts/describe-rule.js" "ApexCRUDViolation" --engine pmd
# Discover fixable violations
node "<skill_dir>/scripts/discover-fixes.js" "./code-analyzer-results-TIMESTAMP.json"
# Apply fixes (after user confirms)
node "<skill_dir>/scripts/apply-fixes.js" "./code-analyzer-results-TIMESTAMP.json"
# Summarize applied fixes
node "<skill_dir>/scripts/summarize-fixes.js" "./code-analyzer-results-TIMESTAMP.json"
# Filter vendor files (jQuery, Bootstrap, *.min.js) before applying fixes
node "<skill_dir>/scripts/filter-violations.js" "./code-analyzer-results-TIMESTAMP.json" "./code-analyzer-results-TIMESTAMP-filtered.json" --report<skill_dir> is the absolute path to the directory containing this SKILL.md. Never use ./scripts/ — that resolves against the user's CWD, not the skill dir.
Any aggregation, filter, or rank question ("which file has the most violations?", "how many PMD issues?", "top rules by count", "break down by severity") is answered by query-results.js — its output already includes topRules, topFiles, and severityCounts.
Ecosystem: This skill is part of a 3-skill Code Analyzer suite —
dx-code-analyzer-run(scans & results) ·dx-code-analyzer-configure(setup, config, CI/CD) ·dx-code-analyzer-custom-rule-create(custom rule authoring).
This skill translates natural-language requests ("scan for security issues", "check my changes") into the correct sf code-analyzer run command, executes scans across any combination of engines/targets/severities, and presents actionable results. When engine-provided fixes are available, it discovers them, asks for user confirmation, applies them safely, and offers verification. Use it for static analysis, security reviews, AppExchange certification, code-quality checks, and finding duplicates/vulnerabilities in Salesforce projects.
In scope: running scans, parsing/filtering/ranking results, applying engine auto-fixes, diff-based scans, all output formats (JSON/HTML/SARIF/CSV/XML), describing/listing rules, scan-failure troubleshooting.
Out of scope: installing/configuring sf or the plugin (→ dx-code-analyzer-configure), writing custom rules/engines (→ dx-code-analyzer-custom-rule-create), AI-generated fixes beyond engine-provided ones, deep refactoring, CI/CD setup (→ dx-code-analyzer-configure).
Allowed tools: Bash (sf code-analyzer, node, git diff, date), Read, Write, Edit. Forbidden: any MCP tool, Agent tool, web tools, other skills, Python, jq, inline scripts/heredocs. This skill owns the complete scan-fix-verify-query-explain workflow end-to-end.
sf code-analyzer run — NOT sf scanner run (deprecated v3).--format flag. Use --output-file <path>.<ext>; the extension determines the format.--output-file with a timestamped name (e.g., ./code-analyzer-results-20260512-143022.json) — do not rely on stdout.run_in_background); timeout 1200000ms for large scans.--format, --engine, --category, --json. Use --rule-selector + --output-file instead.Why: the v4+ CLI redesigned the flag interface; v3 flags now error.
Full flag/selector docs: <skill_dir>/references/flag-reference.md.
User needs: Salesforce CLI (sf), @salesforce/plugin-code-analyzer (v5.x+), Java 11+ (PMD/CPD/SFGE), Node.js 18+ (ESLint/RetireJS), Python 3 (Flow), authenticated org (ApexGuru).
Pre-flight: run sf code-analyzer --help 2>&1 | head -1. If that fails, or if a scan reports an engine startup error (e.g., "PMD failed to start", "java: command not found", "SFGE failed"):
dx-code-analyzer-configure — it handles all setup.If a scan fails for other reasons, see <skill_dir>/references/error-handling.md.
Match the request below; if it matches, jump to Step 3 (Build Command). Otherwise, walk Step 1.
| User Says | Rule Selector | Notes |
|---|---|---|
| "scan my code" / "run code analyzer" | Recommended | Curated set, all file types |
| "check for security issues" / "security review" | all:Security:(1,2) | All engines, Critical+High |
| "scan my changes" / "check the diff" | (see Step 1.5) | Get files via git diff, filter to scannable types, pass via --target |
| "run PMD" / "check my Apex" | pmd | Apex classes and triggers |
| "lint my LWC" / "check my JavaScript" | eslint | JavaScript/TypeScript/LWC |
| "find duplicates" / "check for copy-paste" | cpd | Code clones |
| "check for vulnerabilities" / "scan libraries" | retire-js | JavaScript library CVEs |
| "deep analysis" / "data flow analysis" | sfge | Java 11+, 10–20 min, use --workspace "force-app" |
| "performance analysis" / "governor limits" | apexguru | Authenticated org required |
| "analyze my Flows" | flow | --target **/*.flow-meta.xml, Python 3 |
| "AppExchange security review" | all:Security:(1,2) | See <skill_dir>/references/special-behaviors.md → AppExchange |
Analyze the request along these 7 dimensions; any can combine.
PMD/Apex → pmd · ESLint/JS/TS/lint → eslint · Flows → flow · duplicates/CPD → cpd · vulnerabilities/CVE/RetireJS → retire-js · SFGE/data flow → sfge · performance/ApexGuru → apexguru · regex → regex · everything → all · unspecified → Recommended.
security/OWASP → Security · performance → Performance · best practices → BestPractices · style/format → CodeStyle · design/complexity → Design · bugs → ErrorProne · docs → Documentation.
1=Critical · 2=High · 3=Moderate · 4=Low · 5=Info. "critical only" → 1 · "critical+high" → (1,2) · "moderate and above" → (1,2,3).
If the user names a rule (e.g., "ApexCRUDViolation", "no-unused-vars"): --rule-selector <engine>:<ruleName>, or just <ruleName> if engine is ambiguous.
Partial names: --rule-selector requires the exact full rule name (e.g., @salesforce-ux/slds/no-hardcoded-values-slds2, not no-hardcoded-values). No wildcards. If you are not 100% certain, look it up first — do not guess:
sf code-analyzer rules --rule-selector all 2>&1 | grep -i "USER_KEYWORD"Multiple matches → ask the user which. Zero matches → tell the user nothing matched.
specific path → --target <path> · glob ("all Apex") → --target **/*.cls,**/*.trigger · "my changes"/"diff" → git diff --name-only [base]...HEAD, filter to scannable types, pass as --target · "LWC" → --target **/lwc/** · "Flows" → --target **/*.flow-meta.xml · unspecified → omit (entire workspace).
Diff-filtering details: <skill_dir>/references/special-behaviors.md.
Default JSON. Only change if the user explicitly asks. Name: ./code-analyzer-results-<YYYYMMDD-HHmmss>.<ext> via TIMESTAMP=$(date +%Y%m%d-%H%M%S). Formats: .json (default), .html, .sarif, .csv, .xml.
"new since main" → git diff --name-only main...HEAD → scan those · "since last commit" → HEAD~1 · "vs develop" → develop...HEAD.
Syntax: : = AND, , = OR, () = grouping.
pmdpmd:Securitypmd:2(pmd,eslint):Security:(1,2) = (PMD or ESLint) AND Security AND sev (1 or 2)pmd:ApexCRUDViolationallMore: <skill_dir>/references/command-examples.md.
TIMESTAMP=$(date +%Y%m%d-%H%M%S)
sf code-analyzer run \
--rule-selector <selector> \
--target <targets> \ # optional
--output-file "./code-analyzer-results-${TIMESTAMP}.json" \ # default JSON
--include-fixes \ # always
--workspace <path> # optional--include-fixes (enables Step 6 auto-fix).--target to scan the whole workspace.git diff --name-only → filter scannable types → pass as --target.Special cases (SFGE/ApexGuru/AppExchange/diff): <skill_dir>/references/special-behaviors.md.
Use the Bash tool only — never the run_code_analyzer MCP tool.
date +%Y%m%d-%H%M%S → e.g. 20260512-143022.Starting scan...
Results: ./code-analyzer-results-20260512-143022.json
Log: ./code-analyzer-results-20260512-143022.log
May take several minutes for large codebases.$TIMESTAMP), foreground, timeout 1200000ms, tee to a .log:sf code-analyzer run --rule-selector Recommended \
--output-file "./code-analyzer-results-20260512-143022.json" \
--include-fixes 2>&1 | tee "./code-analyzer-results-20260512-143022.log"<skill_dir>/references/error-handling.md.Run the parse script straight after the scan — do not pause to ask:
node "<skill_dir>/scripts/parse-results.js" "./code-analyzer-results-TIMESTAMP.json"DO NOT:
node scripts/parse-results.js (won't resolve from user's CWD)jq as a substitute for the parse script (shell quoting will break)## Scan Complete
**Found X violations** across Y files.
| Severity | Count |
|----------|-------|
| Critical (1) | X |
| High (2) | X |
| Moderate (3) | X |
| Low (4) | X |
| Info (5) | X |
### Top Issues
| # | Rule | Engine | Sev | File | Line |
|---|------|--------|-----|------|------|
| 1 | ApexCRUDViolation | pmd | 2 | AccountService.cls | 42 |
| ... up to 10 most critical |
### Top Rules by Frequency
| Rule | Engine | Count |
|------|--------|-------|
| no-var | eslint | 170 |
| ... |
Full results: `./code-analyzer-results-20260512-143022.json`Scale to result size: 0 → "no violations found"; 1–10 → all in one table; 11–50 → severity counts + top 10; 50–5000 → counts + top 10 violations + top 10 rules + top 5 files; 5000+ → same, plus suggest narrowing scope (severity/category/folder). Always end with the output path and offer next actions: filter / explain rule / apply fixes.
Large-result handling: <skill_dir>/references/special-behaviors.md.
Engine-provided fixes are deterministic (not AI-generated). Flow: vendor filter (if needed) → discover → present → wait for user confirmation → apply → summarize.
Run if the user said "fix my code" / "project source", or if top-violation files are vendor libs (jQuery, Bootstrap, *.min.js):
node "<skill_dir>/scripts/filter-violations.js" \
"./code-analyzer-results-TIMESTAMP.json" \
"./code-analyzer-results-TIMESTAMP-filtered.json" \
--reportReport: "Excluded X vendor files (Y violations) — jQuery, Bootstrap, etc. Applying fixes to Z project files only." Use the filtered file in 6.2+. Detection logic: <skill_dir>/references/vendor-file-handling.md.
node "<skill_dir>/scripts/discover-fixes.js" "./code-analyzer-results-TIMESTAMP.json"### Engine-Provided Fixes Available
**X of Y violations** have auto-fixes provided by the analysis engine:
| Rule | Engine | Sev | Fixable Count |
|------|--------|-----|---------------|
| no-var | eslint | 3 | 170 |
| ... |
These are safe, deterministic fixes generated by the engines (not AI-generated).
Would you like me to apply these fixes? (yes / no / select specific rules)Stop and wait for the user's reply, even if they originally said "scan and fix everything". Apply only on a fresh "yes" / "apply" / "go ahead" in the next turn.
node "<skill_dir>/scripts/apply-fixes.js" "./code-analyzer-results-TIMESTAMP.json"(Filtered file if 6.1 created one.)
node "<skill_dir>/scripts/summarize-fixes.js" "./code-analyzer-results-TIMESTAMP.json"Then present:
### Engine-Provided Fixes Applied Successfully
**Applied X auto-fixes across Y files.**
| Severity | Fixes Applied |
|----------|---------------|
| Critical (1) | X |
| ... |
| Rule | Fixes Applied |
|------|---------------|
| no-var | 169 |
| ... |
Want me to re-run the scan to verify the fixes resolved the violations?apply-fixes.js.apply-fixes.js against the full (or vendor-filtered) results file as-is.If the user accepts the offer in 6.5, re-run the same scan with a new timestamp (do not overwrite the original). Compare violation counts before vs. after and show the delta — fixes that resolved cleanly will drop out; remaining violations either need manual remediation or are unrelated.
After Step 5, the user may want to drill into specific subsets without re-running the entire scan. This step handles all result-exploration requests.
Activate when the user asks to slice, filter, rank, or explore existing results:
Important: Any question about existing scan results — filtering, ranking, counting, aggregating — MUST use query-results.js. NEVER write inline Python, jq, or ad-hoc scripts to parse the results JSON. The query script already provides topRules, topFiles, and severityCounts in its output.
Run the query script against the same results file from Step 4 (no re-scan needed):
node "<skill_dir>/scripts/query-results.js" "./code-analyzer-results-TIMESTAMP.json" [options]| User says | Options |
|---|---|
| "security violations" | --category Security |
| "PMD issues only" | --engine pmd |
| "critical and high" / "sev 1-2" | --severity 1,2 |
| "in AccountService.cls" | --file AccountService.cls |
| "the ApexCRUDViolation rule" | --rule ApexCRUDViolation |
| "top 20" | --top 20 |
| "sort by file" | --sort file |
| "just give me counts" | --summary |
| "which file has the most violations?" | --sort file --summary (read topFiles) |
| "which file has most PMD violations?" | --engine pmd --summary (read topFiles) |
| "most common rules?" | --summary (read topRules) |
| "how many per engine?" | use Step 5's summary, or run with --engine X --summary per engine |
| Combinations | --engine pmd --severity 1,2 --top 5 |
Output format and presentation templates: <skill_dir>/references/post-scan-workflows.md.
When the user asks "what does this rule mean?" or "how do I fix this?", use this step to look up and explain a specific rule.
node "<skill_dir>/scripts/describe-rule.js" "<rule-name>" [--engine <engine>]Pass --engine when known (from scan context); omit for a broader search. Returns one of success / multiple_matches / not_found. Status handling and templates: <skill_dir>/references/post-scan-workflows.md.
Triggers: "what security rules are available?", "list all PMD rules", "rules for JavaScript", "Recommended rules", "how many ESLint rules?", "rules for Apex".
node "<skill_dir>/scripts/list-rules.js" "<selector>" [options]| User says | Selector | Options |
|---|---|---|
| "security rules" | Security | |
| "PMD rules" | pmd | |
| "ESLint security rules" | eslint:Security | |
| "JavaScript rules" | JavaScript | |
| "Apex rules" | Apex | |
| "Recommended rules" | Recommended | |
| "high severity rules" | (1,2) | |
| "just give me counts" | Recommended | --count-only |
| "top 10 security rules" | Security | --top 10 |
Filters: --engine, --severity, --top (default 100), --count-only. The script pre-validates selector tokens (catches typos like secruity) before calling the CLI. Presentation: <skill_dir>/references/post-scan-workflows.md.
This skill is part of a 3-skill Code Analyzer ecosystem. Hand off cleanly rather than attempting work that belongs to another skill.
dx-code-analyzer-configure:code-analyzer.yml, change severities, or disable engines → delegate entirelydx-code-analyzer-custom-rule-create:dx-code-analyzer-configure completes setup → proceed with scan (Step 1–5)dx-code-analyzer-custom-rule-create finishes creating a rule → proceed with scan targeting the new rule (e.g., --rule-selector pmd:<RuleName>) to verify it worksThis skill owns the complete scan → explore → fix workflow end-to-end. It does NOT own installation, config file management, or rule authoring.
| Item | Why / Fix |
|---|---|
Use timestamped JSON + .log via tee | Prevents overwrite; matches log to results |
--format flag | Removed in v4+; use --output-file <path>.<ext> |
| Foreground, 1200000ms timeout | SFGE can take 10–20 min; backgrounding loses output |
Run scripts with absolute <skill_dir> path | ./scripts/ resolves against the user's CWD, not the skill dir |
| Never apply fixes without confirmation | User must approve code modifications |
| Vendor file check before fixes | If 50%+ vendor (jQuery/Bootstrap/*.min.js), filter first |
| Fix-script order: filter (if needed) → discover → apply → summarize | Skipping summary leaves the user without an outcome report |
SFGE needs explicit --workspace | Otherwise template files cause compilation errors |
| Look up partial rule names first | Guessing returns 0 results; use sf code-analyzer rules |
ONLY Bash tool, never MCP | run_code_analyzer and other MCP tools bypass the script workflow |
| Never invoke other skills for fixes | This skill owns the full workflow end-to-end |
| Query existing results, don't re-scan | Step 7 filters existing JSON instantly |
| Scan returns 0 results | Invalid rule selector — verify with sf code-analyzer rules --rule-selector <selector> |
jq parsing fails | Shell quoting — use parse-results.js / query-results.js instead |
| Inline scripts written by LLM | Never write scripts — use existing ones in <skill_dir>/scripts/ |
| Ranking/aggregation answered by ad-hoc Python | Always use query-results.js; output already has topFiles/topRules/severityCounts |
Scripts (always execute via node with the absolute <skill_dir>/ prefix, never Read):
| File | When to use |
|---|---|
<skill_dir>/scripts/parse-results.js | Step 5 — extract summary from scan JSON |
<skill_dir>/scripts/filter-violations.js | Step 6.1 — exclude vendor files (jQuery, Bootstrap) from fixes |
<skill_dir>/scripts/discover-fixes.js | Step 6.2 — identify fixable violations |
<skill_dir>/scripts/apply-fixes.js | Step 6.4 — apply engine fixes after user confirms |
<skill_dir>/scripts/summarize-fixes.js | Step 6.5 — summarize applied changes |
<skill_dir>/scripts/query-results.js | Step 7 — filter/drill into existing results without re-scanning |
<skill_dir>/scripts/describe-rule.js | Step 8 — look up rule description and documentation |
<skill_dir>/scripts/list-rules.js | Step 9 — list/browse available rules by selector with validation |
References (read on demand):
| File | When to read |
|---|---|
references/quick-start.md | Command-syntax templates |
references/flag-reference.md | Full flag docs, rule-selector syntax |
references/error-handling.md | Scan-failure diagnosis |
references/engine-reference.md | Engine capabilities, file types, rule tags |
references/command-examples.md | Less-common command scenarios |
references/special-behaviors.md | SFGE/ApexGuru/AppExchange/diff/large scans |
references/vendor-file-handling.md | Vendor-file detection and filtering |
references/post-scan-workflows.md | Steps 7–9 — querying, rule description, rule listing |
examples/ contains output-structure validation and command patterns (basic/large/security scans, fix workflows).
© forcedotcom, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 23 other files (scripts, references) in skills/dx-code-analyzer-run of forcedotcom/sf-skills.
Open the folder on GitHubat commit e5164d9
Dx Code Analyzer Run next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dx Code Analyzer Run this skillforcedotcom/sf-skills | 1.1k | — | ~6.3k | Automated safety check: Pass | Apache-2.0 | |
| LobeHub Alint Rule Set Maintenancelobehub/lobehub | 83k | — | ~1.9k | Automated safety check: Pass | Custom licence | |
| Eslint Migrate Optionsbiomejs/biome | 26k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | |
| Code Qualityredis/RedisInsight | 8.9k | — | ~1.2k | Automated safety check: Pass | Custom licence | |
| WebRTC Include Cleanerwebrtc-sdk/webrtc | 446 | 1 repos | ~545 | Automated safety check: Pass | BSD-3-Clause | |
| Obsidian Plugin Development Guidelinesgapmiss/obsidian-plugin-skill | 190 | — | ~4.5k | Automated safety check: Pass | MIT |
lobehub/lobehub
Maintains LobeHub's model-backed alint rule set: writing rules, removing false positives against real code, deciding warn versus error and tracking token cost.
biomejs/biome
A skill your agent uses when biome migrate eslint must preserve configurable ESLint rule options through source-option models, Biome conversions, typed rule variants, and migration fixtures.
redis/RedisInsight
Code-quality standards for RedisInsight: TypeScript strictness, naming conventions (camelCase, PascalCase, UPPERSNAKECASE), linting rules, no any without reason, no !important in styles, and…
webrtc-sdk/webrtc
Runs the WebRTC include-cleaner tool to add missing and remove unused C++ include directives before uploading a CL or after refactoring.
gapmiss/obsidian-plugin-skill
Rules and references for building Obsidian plugins: ESLint rules, TypeScript practices, memory cleanup, API choices, UI standards and the community submission process.
openqodex/openqodex
Code review for the current change, before it is pushed. An agent skill from openqodex/openqodex.
forcedotcom/sf-skills
Declared architecture snapshot for one Agentforce agent: planner, topics, actions, flows, Apex, prompt templates, and NGA plugins.
forcedotcom/sf-skills
Data Cloud 360° view of a single Agentforce session. An agent skill from forcedotcom/sf-skills.
forcedotcom/sf-skills
Apply a Salesforce sandbox post-copy automation JSON config against a target org.
forcedotcom/sf-skills
Apply a Salesforce sandbox post-copy automation JSON config against a target org.
forcedotcom/sf-skills
Apply SLDS-compliant UI using the correct blueprints, styling hooks, utility classes, and icons.
forcedotcom/sf-skills
Lightning Web Components with PICKLES methodology and 165-point scoring.
Works with
Categories
Run Salesforce Code Analyzer to scan code for security, performance, best practice, and code style violations. Dx Code Analyzer Run is an agent skill from forcedotcom/sf-skills. Run Salesforce Code Analyzer to scan code for security, performance, best practice, and code style violations.
Dx Code Analyzer Run fits situations like: : user says scan my code; check security issues; find duplicates; check vulnerable libraries.
Run `npx skills add forcedotcom/sf-skills --skill dx-code-analyzer-run -a claude-code`. Or copy the skill folder (skills/dx-code-analyzer-run in forcedotcom/sf-skills) into .claude/skills/dx-code-analyzer-run in your project. Claude Code loads it when a task matches its description.
Run `npx skills add forcedotcom/sf-skills --skill dx-code-analyzer-run -a codex`. Or copy the skill folder (skills/dx-code-analyzer-run in forcedotcom/sf-skills) into .agents/skills/dx-code-analyzer-run in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forcedotcom/sf-skills --skill dx-code-analyzer-run -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dx-code-analyzer-run, .gemini/skills/dx-code-analyzer-run, .github/skills/dx-code-analyzer-run and .opencode/skills/dx-code-analyzer-run in your project.
Going by SKILL.md and its folder, Dx Code Analyzer Run needs JavaScript for the scripts in its folder and the command-line tools its instructions call (node, sf, git, python3 and jq). Our summary lists: Python 3; Node.js.
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Dx Code Analyzer Run is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 6.3k tokens (SKILL.md is roughly 25k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Dx Code Analyzer Run: LobeHub Alint Rule Set Maintenance (lobehub/lobehub, 83k stars), Eslint Migrate Options (biomejs/biome, 26k stars), Code Quality (redis/RedisInsight, 8.9k stars) and WebRTC Include Cleaner (webrtc-sdk/webrtc, 446 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
forcedotcom (a GitHub organization) maintains it in forcedotcom/sf-skills, which has 1,060 GitHub stars. The repository holds 251 skills in this directory. The repository was last updated on October 7, 2026.
Source: forcedotcom/sf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.