Agent skill

Platform Destructive Deploy

by forcedotcom in forcedotcom/sf-skills

Execute the destructiveChanges.xml delete-and-deploy workflow against a Salesforce org.

Apache-2.0Auto-check: notesSales & Support

Install Platform Destructive Deploy

skills CLI
$ npx skills add forcedotcom/sf-skills --skill platform-destructive-deploy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install forcedotcom/sf-skills platform-destructive-deploy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/builder/salesforce-development/skills/platform-destructive-deploy .claude/skills/platform-destructive-deploy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
platform-destructive-deploy
GitHub stars
1.1k
Token cost
~1.4k tokens
SKILL.md length
511 words
Files
1
Skills in repo
251
Repo updated
First seen
Licence
Apache-2.0

At a glance

Execute the destructiveChanges.xml delete-and-deploy workflow against a Salesforce org.

  • Works in 4 steps: Scope the deletion → Validate → Execute → …
  • The user asks to delete/remove a custom object
  • SKILL.md covers Phase 1 — Scope the deletion, Phase 2 — Validate, Phase 3 — Execute and Phase 4 — Post-delete cleanup, plus 1 more section
  • Calls sf; reaches soap.sforce.com

What it does

Platform Destructive Deploy is an agent skill from forcedotcom/sf-skills. Execute the destructiveChanges.xml delete-and-deploy workflow against a Salesforce org. TRIGGER when the user asks to delete/remove a custom object, field, Apex class, flow, or any metadata component FROM an org, or to perform a 'destructive deploy' / removal as part of a release. Validates first and gates production with explicit confirmation. DO NOT TRIGGER for local file deletion (use Bash), or for net-new deploys (use platform-metadata-deploy).

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Sales & Support, covering CRM management. It works with Salesforce and Bash. The repository describes itself as: Salesforce's curated collection of agent skills for building applications. Optimized for Agentforce Vibes, compatible with all AI tools. The licence is Apache-2.0.

When your agent uses it

  • The user asks to delete/remove a custom object
  • Any metadata component FROM an org
  • Perform a destructive deploy / removal as part of a release
  • Local file deletion (use Bash)

Example prompts

  • “destructive deploy”
  • “/platform-destructive-deploy”

Requirements

  • Pre-approved tools (allowed-tools): Bash, Read, Write, Glob, Grep

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Scope the deletion
  2. Validate
  3. Execute
  4. Post-delete cleanup

What it can do on your machine

Read from SKILL.md and the folder at commit e5164d9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Write
    • Glob
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • sf

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • soap.sforce.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Platform Destructive Deploy loads about 1.4k tokens when it runs. Until then it costs about 120 tokens; SKILL.md has 511 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~120
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Write, Glob, Grep

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from forcedotcom/sf-skills at commit e5164d9, republished under its Apache-2.0 licence (© forcedotcom). 511 words, ~1,444 tokens.

Download SKILL.mdSave it as .claude/skills/platform-destructive-deploy/SKILL.md (or your agent's skills folder).
name
platform-destructive-deploy
description
Execute the destructiveChanges.xml delete-and-deploy workflow against a Salesforce org. TRIGGER when the user asks to delete/remove a custom object, field, Apex class, flow, or any metadata component FROM an org, or to perform a 'destructive deploy' / removal as part of a release. Validates first and gates production with explicit confirmation. DO NOT TRIGGER for local file deletion (use Bash), or for net-new deploys (use platform-metadata-deploy).
allowed-tools
Bash, Read, Write, Glob, Grep

Handling Destructive Changes

Coordinate metadata deletion against a Salesforce org via the destructiveChanges manifest. Runs in three phases: scope → validate → execute, with stricter guardrails for production.

Phase 1 — Scope the deletion

Step 1a — Gather the components to remove

Ask the user (or infer from context) which components to delete. For each, capture:

  • Metadata type (e.g. CustomObject, CustomField, ApexClass, Flow, PermissionSet)
  • API name (e.g. Project__c, Account.Status__c, MyController)
Step 1b — Local dependency scan (best-effort)

Before generating the manifest, scan the local project for references to each component. Use Grep over force-app/:

bash
grep -rn "<componentApiName>" force-app/ --include='*.cls' --include='*.trigger' --include='*.xml' --include='*.js' --include='*.html'

If references are found:

  • List them to the user
  • Recommend either updating those references first OR removing them in the same destructive deploy
  • Do NOT proceed silently — surface the dependency risk
Step 1c — Generate destructiveChanges.xml

Write to manifest/destructiveChangesPre.xml (for pre-deploy deletion) or manifest/destructiveChangesPost.xml (for post-deploy deletion). Use the standard Salesforce metadata format:

xml
<?xml version="1.0" encoding="UTF-8"?>
<Package xmlns="http://soap.sforce.com/2006/04/metadata">
    <types>
        <members>Project__c</members>
        <members>OldThing__c</members>
        <name>CustomObject</name>
    </types>
    <types>
        <members>Account.Status__c</members>
        <name>CustomField</name>
    </types>
    <version>62.0</version>
</Package>

Use the API version from sfdx-project.json's sourceApiVersion.

Group components by metadata type (one <types> block per type). For namespaced fields, use Object.Field notation.

Phase 2 — Validate

ALWAYS validate before executing a destructive deploy:

bash
sf project deploy validate \
  --pre-destructive-changes manifest/destructiveChangesPre.xml \
  --manifest manifest/package.xml \
  --target-org <alias> \
  --test-level RunLocalTests \
  --json

(For post-destructive: use --post-destructive-changes.)

If package.xml doesn't exist, create an empty one alongside (deletion-only deploy needs a package descriptor):

xml
<?xml version="1.0" encoding="UTF-8"?>
<Package xmlns="http://soap.sforce.com/2006/04/metadata">
    <version>62.0</version>
</Package>

If validation fails, surface errors and STOP. Common failure modes:

  • "Cannot delete: referenced by Apex/Flow/Layout" → component still has references
  • "Cannot delete: required for license" → managed-package or license dependency
  • "Insufficient access" → user lacks delete permission

Phase 3 — Execute

Production path

Confirm whether the target is production before executing. The reliable check is the gate's classifier, which resolves the org the same way the deploy hook does (returns production|sandbox|scratch|trial|unknown):

bash
"${CLAUDE_PLUGIN_ROOT}/scripts/sf-deploy-gate" bucket <alias>

unknown means the org type could not be confirmed (usually an incomplete org record). Say so plainly: the deploy gate still allows the deploy, auto-deploy on save stays off for that org, and re-authenticating with sf org login web usually restores the classification.

If the classifier returns production:

  1. Display destructive confirmation banner (mirroring platform-quick-deploy)
  2. List EVERY component that will be deleted
  3. Require explicit "yes, delete from PRODUCTION" confirmation
  4. Reject --purge-on-delete unless the user types it explicitly

The PreToolUse hook (sf-deploy-gate destructive) will already block bare destructive commands against prod — surface that denial to the user, do not work around it.

Show full SKILL.md (161 more words)Show less
Sandbox / Scratch path
bash
sf project deploy start \
  --pre-destructive-changes manifest/destructiveChangesPre.xml \
  --manifest manifest/package.xml \
  --target-org <alias> \
  --json \
  --wait 30

Add --purge-on-delete only if the user explicitly asked to permanently delete (skip the recycle bin).

Phase 4 — Post-delete cleanup

After a successful destructive deploy:

  • Recommend a sf project retrieve start --metadata <Type>:<Name> is NOT useful (component is gone) — instead suggest cleaning up the local source:
    bash
    # Remove the now-deleted local files to keep source tracking accurate
    rm -rf force-app/main/default/<path-to-component>
  • If deleting a custom field with data, remind the user that data is gone (or in the recycle bin until purged)
  • Recommend running tests to confirm no runtime regressions

Rules

  • ALWAYS validate first; NEVER skip Phase 2
  • ALWAYS scan for local references; NEVER delete blindly
  • ALWAYS gate production with explicit user confirmation
  • NEVER add --purge-on-delete without explicit user request
  • NEVER use --ignore-errors on a destructive deploy
  • ALWAYS use the API version from sfdx-project.json, not a hardcoded value
  • If the user is deleting a field with required="true" or that's used in RecordType picklist values, surface the cascade impact before proceeding

© forcedotcom, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/builder/salesforce-development/skills/platform-destructive-deploy of forcedotcom/sf-skills.

Open the folder on GitHubat commit e5164d9

Compare with similar skills

Platform Destructive Deploy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Platform Destructive Deploy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Platform Destructive Deploy this skillforcedotcom/sf-skills1.1k—~1.4kAutomated safety check: NotesApache-2.0
Sf ApexJaganpro/sf-skills424—~2kAutomated safety check: PassMIT
Sf DebugJaganpro/sf-skills424—~1.3kAutomated safety check: PassMIT
Churn Riskindranilbanerjee/digital-marketing-pro8551 repos~2.4kAutomated safety check: PassMIT
Lead Importindranilbanerjee/digital-marketing-pro8551 repos~3.3kAutomated safety check: PassMIT
Pipeline Updateindranilbanerjee/digital-marketing-pro8551 repos~3.3kAutomated safety check: PassMIT

Similar skills

  • Sf Apex

    Jaganpro/sf-skills

    Generates and reviews Salesforce Apex code with 150-point scoring.

    424 GitHub stars~2k tokensUpdated 5 mo ago
    Sales & SupportAuto-check passed
  • Sf Debug

    Jaganpro/sf-skills

    Salesforce debug log analysis and troubleshooting with 100-point scoring.

    424 GitHub stars~1.3k tokensUpdated 5 mo ago
    Sales & SupportAuto-check passed
  • Churn Risk

    indranilbanerjee/digital-marketing-pro

    Score customer segments for churn risk from behavioral signals — email engagement decline, purchase recency, usage drops, support sentiment — producing a 0-100 risk scorecard with four tiers…

    855 GitHub starsUsed in 1 repo~2.4k tokens
    Sales & SupportAuto-check passed
  • Lead Import

    indranilbanerjee/digital-marketing-pro

    Import leads into Salesforce, HubSpot, Zoho, or Pipedrive with validation, deduplication against existing CRM records, lead scoring, consent and compliance checks, and source attribution — then push…

    855 GitHub starsUsed in 1 repo~3.3k tokens
    Sales & SupportAuto-check passed
  • Pipeline Update

    indranilbanerjee/digital-marketing-pro

    Update CRM deals — move stages, change values and close dates, attach notes and activities, create follow-up tasks — with validation against pipeline rules, a before-and-after comparison, and…

    855 GitHub starsUsed in 1 repo~3.3k tokens
    Sales & SupportAuto-check passed
  • Pipeline Review

    majiayu000/claude-skill-registry

    Pipeline analysis composite. An agent skill from majiayu000/claude-skill-registry.

    666 GitHub starsUsed in 2 repos~6.9k tokens
    Sales & SupportAuto-check passed

More from forcedotcom/sf-skills

All 251 skills in this repo
  • Agentforce Architecture Analyze

    forcedotcom/sf-skills

    Declared architecture snapshot for one Agentforce agent: planner, topics, actions, flows, Apex, prompt templates, and NGA plugins.

    1.1k GitHub stars~4.5k tokensUpdated today
    Auto-check passed
  • Agentforce D360 Analyze

    forcedotcom/sf-skills

    Data Cloud 360° view of a single Agentforce session. An agent skill from forcedotcom/sf-skills.

    1.1k GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Apply a Salesforce sandbox post-copy automation JSON config against a target org.

    1.1k GitHub stars~5.3k tokensUpdated today
    Auto-check: notes
  • Apply a Salesforce sandbox post-copy automation JSON config against a target org.

    1.1k GitHub stars~5.4k tokensUpdated today
    Auto-check: notes
  • Design Systems Slds Apply

    forcedotcom/sf-skills

    Apply SLDS-compliant UI using the correct blueprints, styling hooks, utility classes, and icons.

    1.1k GitHub stars~3.7k tokensUpdated today
    Auto-check passed
  • Experience Lwc Generate

    forcedotcom/sf-skills

    Lightning Web Components with PICKLES methodology and 165-point scoring.

    1.1k GitHub stars~2.4k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Platform Destructive Deploy

What does Platform Destructive Deploy do?

Execute the destructiveChanges.xml delete-and-deploy workflow against a Salesforce org. Platform Destructive Deploy is an agent skill from forcedotcom/sf-skills.xml delete-and-deploy workflow against a Salesforce org.

When should I use Platform Destructive Deploy?

Platform Destructive Deploy fits situations like: the user asks to delete/remove a custom object; any metadata component FROM an org; perform a destructive deploy / removal as part of a release; local file deletion (use Bash).

How do I install Platform Destructive Deploy in Claude Code?

Run `npx skills add forcedotcom/sf-skills --skill platform-destructive-deploy -a claude-code`. Or copy the skill folder (plugins/builder/salesforce-development/skills/platform-destructive-deploy in forcedotcom/sf-skills) into .claude/skills/platform-destructive-deploy in your project. Claude Code loads it when a task matches its description.

How do I install Platform Destructive Deploy in Codex?

Run `npx skills add forcedotcom/sf-skills --skill platform-destructive-deploy -a codex`. Or copy the skill folder (plugins/builder/salesforce-development/skills/platform-destructive-deploy in forcedotcom/sf-skills) into .agents/skills/platform-destructive-deploy in your project. Codex loads it when a task matches its description.

Can I use Platform Destructive Deploy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forcedotcom/sf-skills --skill platform-destructive-deploy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/platform-destructive-deploy, .gemini/skills/platform-destructive-deploy, .github/skills/platform-destructive-deploy and .opencode/skills/platform-destructive-deploy in your project.

What does Platform Destructive Deploy need to run?

Going by SKILL.md and its folder, Platform Destructive Deploy needs the command-line tools its instructions call (sf). Its frontmatter pre-approves these tools: Bash, Read, Write, Glob, Grep.

Does Platform Destructive Deploy access the network?

SKILL.md names 1 domain. In commands or code: soap.sforce.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Platform Destructive Deploy safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Platform Destructive Deploy use?

Platform Destructive Deploy is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Platform Destructive Deploy use?

About 1.4k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Platform Destructive Deploy?

Skills that share tags, products or a category with Platform Destructive Deploy: Sf Apex (Jaganpro/sf-skills, 424 stars), Sf Debug (Jaganpro/sf-skills, 424 stars), Churn Risk (indranilbanerjee/digital-marketing-pro, 855 stars) and Lead Import (indranilbanerjee/digital-marketing-pro, 855 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Platform Destructive Deploy?

forcedotcom (a GitHub organization) maintains it in forcedotcom/sf-skills, which has 1,060 GitHub stars. The repository holds 251 skills in this directory. The repository was last updated on October 7, 2026.

Source: forcedotcom/sf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.