Hunt Sqli
elementalsouls/Claude-BugHunter
Hunting skill for sqli vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.
Review a Lightning Web Component for mobile offline compatibility — the Komaci offline static analyzer that pre-primes the data graph for Salesforce Mobile App Plus and Field Service Mobile App.
$ npx skills add forcedotcom/sf-skills --skill mobile-platform-offline-validate -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install forcedotcom/sf-skills mobile-platform-offline-validate --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/mobile-platform-offline-validate .claude/skills/mobile-platform-offline-validate && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "mobile-platform-offline-validate" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/mobile-platform-offline-validate into .claude/skills/mobile-platform-offline-validate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mobile-platform-offline-validate", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/forcedotcom/sf-skills/tree/main/skills/mobile-platform-offline-validateType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add forcedotcom/sf-skills --skill mobile-platform-offline-validate -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install forcedotcom/sf-skills mobile-platform-offline-validate --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/mobile-platform-offline-validate .agents/skills/mobile-platform-offline-validate && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "mobile-platform-offline-validate" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/mobile-platform-offline-validate into .agents/skills/mobile-platform-offline-validate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mobile-platform-offline-validate", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forcedotcom/sf-skills --skill mobile-platform-offline-validate -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install forcedotcom/sf-skills mobile-platform-offline-validate --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/mobile-platform-offline-validate .cursor/skills/mobile-platform-offline-validate && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "mobile-platform-offline-validate" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/mobile-platform-offline-validate into .cursor/skills/mobile-platform-offline-validate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mobile-platform-offline-validate", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/forcedotcom/sf-skills.git --path skills/mobile-platform-offline-validate--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add forcedotcom/sf-skills --skill mobile-platform-offline-validate -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install forcedotcom/sf-skills mobile-platform-offline-validate --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/mobile-platform-offline-validate .gemini/skills/mobile-platform-offline-validate && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "mobile-platform-offline-validate" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/mobile-platform-offline-validate into .gemini/skills/mobile-platform-offline-validate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mobile-platform-offline-validate", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install forcedotcom/sf-skills mobile-platform-offline-validateInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add forcedotcom/sf-skills --skill mobile-platform-offline-validate -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/mobile-platform-offline-validate .github/skills/mobile-platform-offline-validate && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "mobile-platform-offline-validate" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/mobile-platform-offline-validate into .github/skills/mobile-platform-offline-validate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mobile-platform-offline-validate", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forcedotcom/sf-skills --skill mobile-platform-offline-validate -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install forcedotcom/sf-skills mobile-platform-offline-validate --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/mobile-platform-offline-validate .opencode/skills/mobile-platform-offline-validate && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "mobile-platform-offline-validate" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/mobile-platform-offline-validate into .opencode/skills/mobile-platform-offline-validate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mobile-platform-offline-validate", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
mobile-platform-offline-validateReview a Lightning Web Component for mobile offline compatibility — the Komaci offline static analyzer that pre-primes the data graph for Salesforce Mobile App Plus and Field Service Mobile App.
Mobile Platform Offline Validate is an agent skill from forcedotcom/sf-skills. Review a Lightning Web Component for mobile offline compatibility — the Komaci offline static analyzer that pre-primes the data graph for Salesforce Mobile App Plus and Field Service Mobile App. Produces a finding list with code-level fixes covering inline GraphQL queries in @wire configurations, modern lwc:if / lwc:elseif / lwc:else directives, and Komaci ESLint rule violations (private wire properties, non-local reactive references, getter side-effects). Use when the user asks for a "mobile offline review"…
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts and reference files (for example `references/grounding.md`, `references/inline-graphql.md` and `references/komaci-eslint.md`).
It sits in Sales & Support, covering Linting and formatting, CRM management and GraphQL. It works with Salesforce, ESLint and GraphQL. The repository describes itself as: Salesforce's curated collection of agent skills for building applications. Optimized for Agentforce Vibes, compatible with all AI tools. The licence is Apache-2.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit e5164d9. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 3 files in scripts/ (JavaScript and Shell), which the agent can run.
Shell commands in SKILL.md call:
npxFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Mobile Platform Offline Validate loads about 2k tokens when it runs, and up to ~5.7k if it reads all its reference files. Until then it costs about 237 tokens; SKILL.md has 807 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from forcedotcom/sf-skills at commit e5164d9, republished under its Apache-2.0 licence (© forcedotcom). 807 words, ~1,986 tokens.
.claude/skills/mobile-platform-offline-validate/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.Run a structured offline-priming compliance pass over a Lightning Web Component, producing a report of issues found and code-level fixes to bring the component into compliance with Komaci's static analysis requirements for the Salesforce Mobile App Plus and Field Service Mobile App.
Do NOT use this skill for:
mobile-platform-native-capabilities-integrate.reviewing-lws-security, reviewing-lwc-rtl, accessibility-code-review).modules/…).npx eslint with the
@salesforce/eslint-plugin-lwc-graph-analyzer plugin.Mobile Offline Grounding explains the three violation categories and why each blocks offline priming. Read it before judging. The per-reviewer references below are the source of truth for the rules and remediations:
lwc:if conditional rendering compatibility: lwc:if ReviewerIdentify the component bundle: .html, .js/.ts. CSS and meta files are
not in scope for offline priming. If the bundle has multiple HTML
templates, all are reviewed.
Read Mobile Offline Grounding and the three per-reviewer references end-to-end before judging. Cite the specific reviewer when emitting each finding so the report is auditable.
lwc:if / lwc:elseif / lwc:else (HTML)Walk every .html file in the bundle and apply the rules in
lwc:if Reviewer. For each occurrence of
lwc:if={…}, lwc:elseif={…}, or lwc:else, emit a finding with the
exact if:true / if:false rewrite — including the nesting required to
preserve lwc:elseif and lwc:else semantics.
@wire (JS)Walk every .js/.ts file in the bundle and apply the rules in
Inline GraphQL Reviewer. For each @wire
that references a gql template literal directly (or via a top-level
constant), emit a finding that names a concrete getter and shows the
rewritten @wire configuration.
Run the Komaci ESLint analyzer over the bundle's JS file using the
bundled script. It applies the
@salesforce/eslint-plugin-lwc-graph-analyzer recommended ruleset with
the bundleAnalyzer processor enabled.
scripts/run-komaci.sh path/to/component.jsThe script requires @salesforce/eslint-plugin-lwc-graph-analyzer to
be resolvable from the working directory, and the component's sibling
HTML templates must live next to the JS file (the plugin's
bundleAnalyzer processor uses them to resolve the offline data
graph). Output is ESLint --format json on stdout.
For each messages[*] entry in the output, group by ruleId and look
up the per-rule remediation in
Komaci ESLint Reviewer. Emit a finding
per (rule, line) pair with the exact remediation text from the
reference; do not invent new advice. See the reference for the manual
npx eslint ... invocation if the script is unavailable in the runtime
environment.
Emit a report in this shape:
## Mobile Offline (Komaci priming)
- <reviewer> — <file>:<startLine>:<startColumn>-<endLine>:<endColumn> — <type>
Description: <verbatim from the reviewer reference>
Intent analysis: <verbatim from the reviewer reference>
Suggested action: <verbatim from the reviewer reference>
Code: |
<source snippet from startLine through endLine, optional but
recommended when the violation spans multiple lines>
Applied: yes/no
## Summary
- <n> issues found; <m> fixed; <k> deferred (with reason)For Komaci ESLint findings, take startLine/startColumn/endLine/
endColumn from the ESLint message's line/column/endLine/endColumn.
For Inline GraphQL and lwc:if findings, supply the line/column range you
observed in the source. If endLine/endColumn are not available for a
finding, fall back to <file>:<startLine> and omit the trailing range.
Cite the reviewer (Inline GraphQL / lwc:if / Komaci ESLint rule id) on every finding.
Apply the remediations directly when the user asked for fixes. If a
remediation conflicts with the component's behavior outside offline (e.g.
the developer relies on lwc:elseif for readability and the user is not
yet shipping to mobile offline), surface the conflict in the deferred list
rather than silently rewriting.
lwc:if / lwc:elseif / lwc:else flagged or absent.@wire referencing gql checked; inline queries extracted to
a getter.npx eslint cannot find the plugin — install
@salesforce/eslint-plugin-lwc-graph-analyzer in the workspace, or use a
pinned local install path. The plugin is the canonical source of Komaci
rules.bundleAnalyzer related errors — the recommended config drives the
bundle processor; do not strip it. The processor expects sibling HTML
files to be discoverable. If running on a stripped-down JS file, supply
the matching HTML in the temp directory.bundleAnalyzer with empty
rules). Some rules require the HTML to be present alongside the JS.lwc:if from the dedicated reviewer — the Komaci
plugin does not check templates; the lwc:if check is HTML-only and
comes from Step 3. Findings from Step 5 are JS-only.© forcedotcom, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 7 other files (scripts, references) in skills/mobile-platform-offline-validate of forcedotcom/sf-skills.
Open the folder on GitHubat commit e5164d9
Mobile Platform Offline Validate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Mobile Platform Offline Validate this skillforcedotcom/sf-skills | 1.1k | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| Hunt Sqlielementalsouls/Claude-BugHunter | 4.8k | — | ~5.5k | Automated safety check: Pass | MIT | |
| Copilot PR Autopilotgithub/awesome-copilot | 40k | — | ~3.4k | Automated safety check: Pass | MIT | |
| Shopify AI Toolkit Wrapperjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~1.5k | Automated safety check: Pass | MIT | |
| Eslint Migrate Optionsbiomejs/biome | 26k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | |
| Boundaries Architectjavierbrea/eslint-plugin-boundaries | 997 | — | ~4.2k | Automated safety check: Pass | MIT |
elementalsouls/Claude-BugHunter
Hunting skill for sqli vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.
github/awesome-copilot
Copilot left 14 review comments on your PR — half are nits. An agent skill from github/awesome-copilot.
jeremylongshore/tons-of-skills-marketplace
Integrate Shopify's AI Toolkit MCP server with Claude Code for GraphQL validation, Liquid linting, and documentation search.
biomejs/biome
A skill your agent uses when biome migrate eslint must preserve configurable ESLint rule options through source-option models, Biome conversions, typed rule variants, and migration fixtures.
javierbrea/eslint-plugin-boundaries
Act as a software architect: analyze a repository's folder structure and cross-file import dependencies, detect its architectural pattern, design element/file boundaries with the user, and configure…
openqodex/openqodex
Code review for the current change, before it is pushed. An agent skill from openqodex/openqodex.
forcedotcom/sf-skills
Declared architecture snapshot for one Agentforce agent: planner, topics, actions, flows, Apex, prompt templates, and NGA plugins.
forcedotcom/sf-skills
Data Cloud 360° view of a single Agentforce session. An agent skill from forcedotcom/sf-skills.
forcedotcom/sf-skills
Apply a Salesforce sandbox post-copy automation JSON config against a target org.
forcedotcom/sf-skills
Apply a Salesforce sandbox post-copy automation JSON config against a target org.
forcedotcom/sf-skills
Apply SLDS-compliant UI using the correct blueprints, styling hooks, utility classes, and icons.
forcedotcom/sf-skills
Lightning Web Components with PICKLES methodology and 165-point scoring.
Works with
Categories
Review a Lightning Web Component for mobile offline compatibility — the Komaci offline static analyzer that pre-primes the data graph for Salesforce Mobile App Plus and Field Service Mobile App. Mobile Platform Offline Validate is an agent skill from forcedotcom/sf-skills. Review a Lightning Web Component for mobile offline compatibility — the Komaci offline static analyzer that pre-primes the data graph for Salesforce Mobile App Plus and Field Service Mobile App.
Mobile Platform Offline Validate fits situations like: the user asks for a mobile offline review; offline priming audit; offline priming failure; offline data graph error.
Run `npx skills add forcedotcom/sf-skills --skill mobile-platform-offline-validate -a claude-code`. Or copy the skill folder (skills/mobile-platform-offline-validate in forcedotcom/sf-skills) into .claude/skills/mobile-platform-offline-validate in your project. Claude Code loads it when a task matches its description.
Run `npx skills add forcedotcom/sf-skills --skill mobile-platform-offline-validate -a codex`. Or copy the skill folder (skills/mobile-platform-offline-validate in forcedotcom/sf-skills) into .agents/skills/mobile-platform-offline-validate in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forcedotcom/sf-skills --skill mobile-platform-offline-validate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mobile-platform-offline-validate, .gemini/skills/mobile-platform-offline-validate, .github/skills/mobile-platform-offline-validate and .opencode/skills/mobile-platform-offline-validate in your project.
Going by SKILL.md and its folder, Mobile Platform Offline Validate needs JavaScript and a shell for the scripts in its folder and the command-line tools its instructions call (npx). Our summary lists: Node.js; A Bash shell.
SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Mobile Platform Offline Validate is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.7k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Mobile Platform Offline Validate: Hunt Sqli (elementalsouls/Claude-BugHunter, 4.8k stars), Copilot PR Autopilot (github/awesome-copilot, 40k stars), Shopify AI Toolkit Wrapper (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Eslint Migrate Options (biomejs/biome, 26k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
forcedotcom (a GitHub organization) maintains it in forcedotcom/sf-skills, which has 1,060 GitHub stars. The repository holds 251 skills in this directory. The repository was last updated on October 7, 2026.
Source: forcedotcom/sf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.