Agent skill

Dx Org Analyze

by forcedotcom in forcedotcom/sf-skills

Compare two Salesforce orgs side-by-side and produce a comparison report with drift score, or analyze a single org to produce an inventory covering metadata components, org permissions, system…

Apache-2.0Auto-check passedSales & Support

Install Dx Org Analyze

skills CLI
$ npx skills add forcedotcom/sf-skills --skill dx-org-analyze -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install forcedotcom/sf-skills dx-org-analyze --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dx-org-analyze .claude/skills/dx-org-analyze && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dx-org-analyze
GitHub stars
1.1k
Token cost
~2.7k tokens
SKILL.md length
974 words
Files
12 (incl. scripts, references)
Skills in repo
251
Repo updated
First seen
Licence
Apache-2.0

At a glance

Compare two Salesforce orgs side-by-side and produce a comparison report with drift score, or analyze a single org to produce an inventory covering metadata components, org permissions, system…

  • Works in 6 steps: List Authenticated Orgs → User Selects Two Orgs → Validate Connectivity → …
  • The user wants to compare orgs
  • SKILL.md covers Tool Restrictions, Data Access Hierarchy, Authentication Rules and Workflow, plus 6 more sections
  • Runs Python and Shell scripts from its folder; calls sf and python3

What it does

Dx Org Analyze is an agent skill from forcedotcom/sf-skills. Compare two Salesforce orgs side-by-side and produce a comparison report with drift score, or analyze a single org to produce an inventory covering metadata components, org permissions, system permissions, profiles, installed packages, licenses, and org limits. Use this skill when the user wants to compare orgs, diff orgs, audit configuration drift, find what changed between two environments, compare sandbox against production, or analyze a single org. Trigger phrases include: 'compare orgs', 'compare these 2…

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 15 other files, including scripts and reference files (for example `README.md`, `references/collection-details.md` and `references/report-format.md`).

It sits in Sales & Support, covering CRM management. It works with Salesforce. The repository describes itself as: Salesforce's curated collection of agent skills for building applications. Optimized for Agentforce Vibes, compatible with all AI tools. The licence is Apache-2.0.

When your agent uses it

  • The user wants to compare orgs
  • Audit configuration drift
  • Find what changed between two environments
  • Compare sandbox against production

Example prompts

  • “compare orgs”
  • “compare these 2 orgs”
  • “compare my orgs”
  • “/dx-org-analyze”

Requirements

  • Python 3
  • A Bash shell

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. List Authenticated Orgs
  2. User Selects Two Orgs
  3. Validate Connectivity
  4. Collect Data (per org)
  5. Compute Diff and Report
  6. Present Results

What it can do on your machine

Read from SKILL.md and the folder at commit e5164d9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Python and Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • sf
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dx Org Analyze loads about 2.7k tokens when it runs, and up to ~4.3k if it reads all its reference files. Until then it costs about 252 tokens; SKILL.md has 974 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~252
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from forcedotcom/sf-skills at commit e5164d9, republished under its Apache-2.0 licence (© forcedotcom). 974 words, ~2,728 tokens.

Download SKILL.mdSave it as .claude/skills/dx-org-analyze/SKILL.md (or your agent's skills folder). This skill also uses 11 other files; get the full folder from GitHub.
name
dx-org-analyze
description
Compare two Salesforce orgs side-by-side and produce a comparison report with drift score, or analyze a single org to produce an inventory covering metadata components, org permissions, system permissions, profiles, installed packages, licenses, and org limits. Use this skill when the user wants to compare orgs, diff orgs, audit configuration drift, find what changed between two environments, compare sandbox against production, or analyze a single org. Trigger phrases include: 'compare orgs', 'compare these 2 orgs', 'compare my orgs', 'diff orgs', 'org diff', 'what is different between these orgs', 'compare metadata', 'org comparison', 'audit org differences', 'compare sandbox to production', 'introspect org', 'org inventory', 'what is in my org', 'analyze org', 'org analysis', 'analyze my org', 'analyze my Salesforce org'. Do NOT use for retrieving metadata (use platform-metadata-retrieve), deploying metadata (use platform-metadata-deploy), or switching orgs (use dx-org-switch).
metadata.version
1.0
metadata.minApiVersion
62.0
metadata.domains
Developer Experience
metadata.relatedSkills
dx-org-manage, dx-org-switch, platform-metadata-deploy, platform-metadata-retrieve

Tool Restrictions

Use ONLY the Bash tool to execute all sf CLI commands and Python scripts. Always include --json for sf commands. Do NOT use mcp__salesforce_dx__* tools.

Output artifacts for eval/testing: When an output directory is available, write results there. After executing the skill: (1) if the user specified an output path, write there immediately; (2) otherwise run [ -d force-app/main/adk-eval-output/ ] && echo 'force-app/main/adk-eval-output' to detect the eval directory; (3) write the full JSON result to <output-dir>/dx-org-analyze-result.json and the markdown report to <output-dir>/dx-org-analyze-result.md.


Data Access Hierarchy

When querying org data, always follow this priority order:

  1. SF CLI commands — Preferred. Use sf org list metadata-types, sf org list metadata, sf org display, sf data query, sf limits api display, etc.
  2. Direct REST/Tooling API calls — Last resort, only when SF CLI cannot provide the data.

Never bypass this hierarchy. If an SF CLI command exists for the operation, use it even if a direct API call would be simpler.


Authentication Rules

  • All authentication MUST go through SF CLI (sf org login web, sf org login jwt, sf org login access-token).
  • Never accept raw credentials (username + password), session IDs, or access tokens directly from the user.
  • The collection script obtains its access token exclusively via sf org display --json.

Workflow

Step 0: List Authenticated Orgs

Run this command to discover all authenticated orgs:

bash
sf org list --json --skip-connection-status

Parse the JSON output. Collect orgs from all buckets (devHubs, nonScratchOrgs, scratchOrgs, sandboxes, other). Present authenticated orgs in a readable table:

#AliasUsernameInstance URLOrg IDType

If fewer than 2 orgs are authenticated but at least 1 is available, offer the single-org introspect mode (see Introspect Workflow below). If no orgs are authenticated, STOP and advise:

You need at least 1 authenticated org. Run sf org login web --alias <name> to authenticate.

If the user explicitly requests a single-org introspection or inventory, use the Introspect Workflow regardless of how many orgs are available.

Step 1: User Selects Two Orgs

Ask the user to select two orgs from the list. Both must be explicitly named — do NOT allow implicit/default orgs.

Select two orgs to compare. Which is the source (reference/expected state)? Which is the target (to compare against)?

Accept: alias, username, or number from the list. Resolve each selection to a concrete username. If an org lacks an alias, prompt the user to assign one. Confirm:

Comparing:

  • Source: <alias> (<username>)
  • Target: <alias> (<username>)
Step 2: Validate Connectivity

For each org, confirm reachability with a lightweight query that does not expose secrets:

bash
sf data query --target-org <alias-or-username> --query "SELECT Id FROM Organization LIMIT 1" --json

If the query succeeds (exit 0 and a record is returned), the org is connected. If it fails with INVALID_SESSION_ID or auth errors:

bash
sf org login web --alias <alias>
Step 3: Collect Data (per org)

Generate a unique run ID and run the collection script for each org:

bash
RUN_ID=$(date +%Y%m%d-%H%M%S)

python3 ./scripts/collect_org_data.py \
  --org-alias "$SOURCE_ORG" \
  --output /tmp/dx-org-comparison-${RUN_ID}-source

python3 ./scripts/collect_org_data.py \
  --org-alias "$TARGET_ORG" \
  --output /tmp/dx-org-comparison-${RUN_ID}-target

Exit codes: 0 = success, 1 = fatal error (report stderr to user), 2 = session expired (re-authenticate Step 2 and retry).

For details on what the collection script gathers, see references/collection-details.md.

Step 4: Compute Diff and Report
bash
python3 ./scripts/compute_diff.py \
  --org-a /tmp/dx-org-comparison-${RUN_ID}-source \
  --org-b /tmp/dx-org-comparison-${RUN_ID}-target \
  --output /tmp/dx-org-comparison-${RUN_ID} \
  --format both \
  --org-a-label "Source" \
  --org-b-label "Target"

Use --show-shared if the user wants shared components listed in detail.

Step 5: Present Results

Read /tmp/dx-org-comparison-${RUN_ID}.md and present to the user. If the user asks follow-up questions, use /tmp/dx-org-comparison-${RUN_ID}.json for data lookups. Then resolve the output directory and copy both files there:

bash
OUTPUT_DIR=""
if [ -n "$USER_OUTPUT_PATH" ]; then
  OUTPUT_DIR="$USER_OUTPUT_PATH"
elif [ -d "force-app/main/adk-eval-output" ]; then
  OUTPUT_DIR="force-app/main/adk-eval-output"
fi

if [ -n "$OUTPUT_DIR" ]; then
  cp /tmp/dx-org-comparison-${RUN_ID}.json "$OUTPUT_DIR/dx-org-analyze-result.json"
  cp /tmp/dx-org-comparison-${RUN_ID}.md "$OUTPUT_DIR/dx-org-analyze-result.md"
fi

Introspect Workflow (Single-Org Mode)

Use this workflow when the user wants to inspect a single org's configuration, or when only one org is authenticated.

Introspect Step 1: Validate Connectivity
bash
sf data query --target-org <alias-or-username> --query "SELECT Id FROM Organization LIMIT 1" --json
Introspect Step 2: Collect Data
bash
RUN_ID=$(date +%Y%m%d-%H%M%S)

python3 ./scripts/collect_org_data.py \
  --org-alias "$ORG" \
  --output /tmp/dx-org-analysis-${RUN_ID}
Introspect Step 3: Generate Report
bash
python3 ./scripts/introspect_org.py \
  --org /tmp/dx-org-analysis-${RUN_ID} \
  --output /tmp/dx-org-analysis-${RUN_ID} \
  --format both \
  --label "OrgName"
Show full SKILL.md (403 more words)Show less
Introspect Step 4: Present Results

Read /tmp/dx-org-analysis-${RUN_ID}.md and present to the user. The report covers: metadata inventory, org settings, org limits, installed packages, licenses, system permissions, and deep data records. Then resolve the output directory and copy both files there:

bash
OUTPUT_DIR=""
if [ -n "$USER_OUTPUT_PATH" ]; then
  OUTPUT_DIR="$USER_OUTPUT_PATH"
elif [ -d "force-app/main/adk-eval-output" ]; then
  OUTPUT_DIR="force-app/main/adk-eval-output"
fi

if [ -n "$OUTPUT_DIR" ]; then
  cp /tmp/dx-org-analysis-${RUN_ID}.json "$OUTPUT_DIR/dx-org-analyze-result.json"
  cp /tmp/dx-org-analysis-${RUN_ID}.md "$OUTPUT_DIR/dx-org-analyze-result.md"
fi

Report Structure

The generated report includes:

  1. Drift Score — Weighted overall score (60% metadata, 30% permissions, 10% profiles) with severity level (LOW/MODERATE/HIGH/CRITICAL)
  2. Summary Statistics — Counts per metadata type with Identical/Different columns from deep data
  3. Metadata Components by Type — Only-in-Source, only-in-Target, shared per type
  4. Profiles — Shared, source-only, target-only
  5. Installed Packages — Version comparison, only-in-Source, only-in-Target
  6. Package Components — Namespaced components grouped by namespace
  7. Org Permissions — Boolean enabled/disabled diffs by category, plus value diffs
  8. System Permissions — PermissionsXxx fields on PermissionSet, per-set diffs
  9. Org Values & Limits — Grouped by Identity, Storage, API, Feature Limits
  10. Licenses — User, Permission Set, Package license quantity diffs
  11. Deep Data — Content-level diffs for Apex, Flows, Validation Rules, Custom Fields, etc.

Rules / Constraints

ConstraintRationale
Always use --json with sf commandsStructured output for reliable parsing
Resolve orgs to usernames, not aliasesAliases can be ambiguous; usernames are unique
Skip expired and disconnected orgsCannot query metadata from inaccessible orgs
Read-only — never deploy or modifyThis skill compares only, never mutates either org
SF CLI auth onlyAll authentication through SF CLI credential store
Both orgs must be explicitNever compare unnamed or implicit/default orgs

Troubleshooting

IssueResolution
"No org found for <alias>"Org not authenticated — run sf org login web --alias <name>
Fewer than 2 authenticated orgsAuthenticate additional orgs before comparing
"INVALID_SESSION_ID" or auth errorsSession expired — re-run sf org login web --alias <name>
Collection script exits with code 2Session expired — re-authenticate and retry
API limit errors during metadata listingUse --skip-deep-data for a faster pass with less detail
Edition differences (DE vs EE)Many differences are edition-inherent, not configuration drift
Large orgs timeout on deep dataUse --skip-deep-data flag; run full deep data on targeted follow-ups

Cross-Skill Integration

NeedDelegate to
Retrieve specific metadata from an orgplatform-metadata-retrieve
Deploy metadata to an orgplatform-metadata-deploy
Create a scratch org for comparisondx-org-manage
Switch default org after comparisondx-org-switch

Reference File Index

FileWhen to read
references/collection-details.mdFor details on what the collection script gathers and how
references/report-format.mdFor drift score formula and report section details
scripts/collect_org_data.pyData collection script (per org)
scripts/compute_diff.pyDiff computation and report generation script
scripts/introspect_org.pySingle-org introspection report script

© forcedotcom, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 11 other files (scripts, references) in skills/dx-org-analyze of forcedotcom/sf-skills.

  • SKILL.md
  • README.md
  • references/collection-details.md
  • references/report-format.md
  • scripts/collect_org_data.py
  • scripts/compute_diff.py
  • scripts/introspect_org.py
  • tests/README.md
  • tests/fixtures/org_a.json
  • tests/fixtures/org_b.json
  • tests/test_compute_diff.sh
  • tests/test_consistency.sh

Open the folder on GitHubat commit e5164d9

Compare with similar skills

Dx Org Analyze next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dx Org Analyze compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dx Org Analyze this skillforcedotcom/sf-skills1.1k—~2.7kAutomated safety check: PassApache-2.0
Soql Lib Query Builderbeyond-the-cloud-dev/soql-lib154—~4.3kAutomated safety check: PassMIT
Sf DatacloudJaganpro/sf-skills424—~2.7kAutomated safety check: PassMIT
Soql Lib Selectorbeyond-the-cloud-dev/soql-lib154—~2kAutomated safety check: PassMIT
Dev SetupPortwood-Global-Solutions/Portwood125—~1.1kAutomated safety check: PassApache-2.0
Sf FlowJaganpro/sf-skills424—~1.8kAutomated safety check: PassMIT

Similar skills

  • Soql Lib Query Builder

    beyond-the-cloud-dev/soql-lib

    Builds Salesforce SOQL queries using the SOQL Lib fluent builder API (SOQL.cls).

    154 GitHub stars~4.3k tokensUpdated 5 days ago
    Sales & SupportAuto-check passed
  • Sf Datacloud

    Jaganpro/sf-skills

    Salesforce Data Cloud product orchestrator for connect→prepare→harmonize→segment→act workflows.

    424 GitHub stars~2.7k tokensUpdated 5 mo ago
    Sales & SupportAuto-check passed
  • Soql Lib Selector

    beyond-the-cloud-dev/soql-lib

    Creates Salesforce Apex selector classes using the SOQL Lib selector pattern.

    154 GitHub stars~2k tokensUpdated 5 days ago
    Sales & SupportAuto-check passed
  • Dev Setup

    Portwood-Global-Solutions/Portwood

    Get from a fresh clone of Portwood to a working, fully-tested Salesforce org.

    125 GitHub stars~1.1k tokensUpdated today
    Sales & SupportAuto-check passed
  • Sf Flow

    Jaganpro/sf-skills

    Creates and validates Salesforce Flows with 110-point scoring.

    424 GitHub stars~1.8k tokensUpdated 5 mo ago
    Sales & SupportAuto-check passed
  • Google Maps Export

    gmapsscraper/google-maps-agent-skills

    Export Google Maps business data to CSV, JSON, or CRM format (HubSpot, Pipedrive, Salesforce).

    132 GitHub stars~1.2k tokensUpdated 4 mo ago
    Sales & SupportAuto-check passed

More from forcedotcom/sf-skills

All 251 skills in this repo
  • Agentforce Architecture Analyze

    forcedotcom/sf-skills

    Declared architecture snapshot for one Agentforce agent: planner, topics, actions, flows, Apex, prompt templates, and NGA plugins.

    1.1k GitHub stars~4.5k tokensUpdated yesterday
    Auto-check passed
  • Agentforce D360 Analyze

    forcedotcom/sf-skills

    Data Cloud 360° view of a single Agentforce session. An agent skill from forcedotcom/sf-skills.

    1.1k GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Apply a Salesforce sandbox post-copy automation JSON config against a target org.

    1.1k GitHub stars~5.3k tokensUpdated yesterday
    Auto-check: notes
  • Apply a Salesforce sandbox post-copy automation JSON config against a target org.

    1.1k GitHub stars~5.4k tokensUpdated yesterday
    Auto-check: notes
  • Design Systems Slds Apply

    forcedotcom/sf-skills

    Apply SLDS-compliant UI using the correct blueprints, styling hooks, utility classes, and icons.

    1.1k GitHub stars~3.7k tokensUpdated yesterday
    Auto-check passed
  • Experience Lwc Generate

    forcedotcom/sf-skills

    Lightning Web Components with PICKLES methodology and 165-point scoring.

    1.1k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Dx Org Analyze

What does Dx Org Analyze do?

Compare two Salesforce orgs side-by-side and produce a comparison report with drift score, or analyze a single org to produce an inventory covering metadata components, org permissions, system…. Dx Org Analyze is an agent skill from forcedotcom/sf-skills. Compare two Salesforce orgs side-by-side and produce a comparison report with drift score, or analyze a single org to produce an inventory covering metadata components, org permissions, system permissions, profiles, installed packages, licenses, and org limits.

When should I use Dx Org Analyze?

Dx Org Analyze fits situations like: the user wants to compare orgs; audit configuration drift; find what changed between two environments; compare sandbox against production.

How do I install Dx Org Analyze in Claude Code?

Run `npx skills add forcedotcom/sf-skills --skill dx-org-analyze -a claude-code`. Or copy the skill folder (skills/dx-org-analyze in forcedotcom/sf-skills) into .claude/skills/dx-org-analyze in your project. Claude Code loads it when a task matches its description.

How do I install Dx Org Analyze in Codex?

Run `npx skills add forcedotcom/sf-skills --skill dx-org-analyze -a codex`. Or copy the skill folder (skills/dx-org-analyze in forcedotcom/sf-skills) into .agents/skills/dx-org-analyze in your project. Codex loads it when a task matches its description.

Can I use Dx Org Analyze in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forcedotcom/sf-skills --skill dx-org-analyze -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dx-org-analyze, .gemini/skills/dx-org-analyze, .github/skills/dx-org-analyze and .opencode/skills/dx-org-analyze in your project.

What does Dx Org Analyze need to run?

Going by SKILL.md and its folder, Dx Org Analyze needs Python and a shell for the scripts in its folder and the command-line tools its instructions call (sf and python3). Our summary lists: Python 3; A Bash shell.

Does Dx Org Analyze access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Dx Org Analyze safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Dx Org Analyze use?

Dx Org Analyze is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dx Org Analyze use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.6k tokens, read only when the agent opens those files.

What are the alternatives to Dx Org Analyze?

Skills that share tags, products or a category with Dx Org Analyze: Soql Lib Query Builder (beyond-the-cloud-dev/soql-lib, 154 stars), Sf Datacloud (Jaganpro/sf-skills, 424 stars), Soql Lib Selector (beyond-the-cloud-dev/soql-lib, 154 stars) and Dev Setup (Portwood-Global-Solutions/Portwood, 125 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dx Org Analyze?

forcedotcom (a GitHub organization) maintains it in forcedotcom/sf-skills, which has 1,060 GitHub stars. The repository holds 251 skills in this directory. The repository was last updated on October 7, 2026.

Source: forcedotcom/sf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.