Atdd Mutate
swingerman/engineer
A skill your agent uses to add a third validation layer to the ATDD workflow — after acceptance tests verify WHAT and unit tests verify HOW, mutation testing verifies the tests actually catch bugs.
Configure, run, and audit DsarPolicy Right-to-Portability exports end to end: author the data map over a subject's related records, resolve a request's subject (email/name/id) to a root-entity…
$ npx skills add forcedotcom/sf-skills --skill platform-dsar-policy-manage -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install forcedotcom/sf-skills platform-dsar-policy-manage --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/platform-dsar-policy-manage .claude/skills/platform-dsar-policy-manage && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "platform-dsar-policy-manage" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/platform-dsar-policy-manage into .claude/skills/platform-dsar-policy-manage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "platform-dsar-policy-manage", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/forcedotcom/sf-skills/tree/main/skills/platform-dsar-policy-manageType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add forcedotcom/sf-skills --skill platform-dsar-policy-manage -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install forcedotcom/sf-skills platform-dsar-policy-manage --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/platform-dsar-policy-manage .agents/skills/platform-dsar-policy-manage && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "platform-dsar-policy-manage" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/platform-dsar-policy-manage into .agents/skills/platform-dsar-policy-manage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "platform-dsar-policy-manage", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forcedotcom/sf-skills --skill platform-dsar-policy-manage -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install forcedotcom/sf-skills platform-dsar-policy-manage --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/platform-dsar-policy-manage .cursor/skills/platform-dsar-policy-manage && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "platform-dsar-policy-manage" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/platform-dsar-policy-manage into .cursor/skills/platform-dsar-policy-manage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "platform-dsar-policy-manage", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/forcedotcom/sf-skills.git --path skills/platform-dsar-policy-manage--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add forcedotcom/sf-skills --skill platform-dsar-policy-manage -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install forcedotcom/sf-skills platform-dsar-policy-manage --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/platform-dsar-policy-manage .gemini/skills/platform-dsar-policy-manage && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "platform-dsar-policy-manage" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/platform-dsar-policy-manage into .gemini/skills/platform-dsar-policy-manage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "platform-dsar-policy-manage", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install forcedotcom/sf-skills platform-dsar-policy-manageInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add forcedotcom/sf-skills --skill platform-dsar-policy-manage -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/platform-dsar-policy-manage .github/skills/platform-dsar-policy-manage && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "platform-dsar-policy-manage" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/platform-dsar-policy-manage into .github/skills/platform-dsar-policy-manage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "platform-dsar-policy-manage", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forcedotcom/sf-skills --skill platform-dsar-policy-manage -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install forcedotcom/sf-skills platform-dsar-policy-manage --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/platform-dsar-policy-manage .opencode/skills/platform-dsar-policy-manage && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "platform-dsar-policy-manage" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/platform-dsar-policy-manage into .opencode/skills/platform-dsar-policy-manage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "platform-dsar-policy-manage", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
platform-dsar-policy-manageConfigure, run, and audit DsarPolicy Right-to-Portability exports end to end: author the data map over a subject's related records, resolve a request's subject (email/name/id) to a root-entity…
Platform Dsar Policy Manage is an agent skill from forcedotcom/sf-skills. Configure, run, and audit DsarPolicy Right-to-Portability exports end to end: author the data map over a subject's related records, resolve a request's subject (email/name/id) to a root-entity record, run an export against an ACTIVE policy (poll a couple of times, then ask before continuing; download once terminal), and read run history. Use when the user needs to set up, edit, execute, or inspect a DsarPolicy or Right-to-Portability (RTP) export, or audit which personal data a policy does not cover yet. TRIGGER…
Its SKILL.md is about 5.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 12 other files, including scripts and reference files (for example `references/configure.md`, `references/export-and-history.md` and `references/gap-analysis-guide.md`).
It sits in Testing & QA, covering Privacy and GDPR, Test coverage and End-to-end testing. The repository describes itself as: Salesforce's curated collection of agent skills for building applications. Optimized for Agentforce Vibes, compatible with all AI tools. The licence is Apache-2.0.
8 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 4bbae5c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 3 files in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
sfpython3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Platform Dsar Policy Manage loads about 5.2k tokens when it runs, and up to ~14k if it reads all its reference files. Until then it costs about 261 tokens; SKILL.md has 2,612 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from forcedotcom/sf-skills at commit 4bbae5c, republished under its Apache-2.0 licence (© forcedotcom). 2,612 words, ~5,224 tokens.
.claude/skills/platform-dsar-policy-manage/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.Operate a DsarPolicy — the metadata driving a Right-to-Portability (RTP) export — across
its lifecycle: configure the tree, run an export, audit runs. A DsarPolicy is a
read/export map: it names which of a subject's records an export collects. It never deletes
anything. The value here is judgment, not XML plumbing.
FIRST LINE OF EVERY RESPONSE — do not narrate the skill. Your first output token is work or the answer, never a play-by-play. Do not open with "This is a coverage-gap audit / Workflow D…", "Let me read the skill's guide/mechanics…", "Per rule #1…", or "Let me discover the SOR…". Don't name the workflow, announce which reference files you're about to read, or describe your method before doing it — just start doing it (call the tool) and, when done, present the result. This is load-bearing call #8, stated up front because it governs your very first token. A plain-language sentence about the user's data/org is fine; a sentence about the skill, its workflows, rules, tools, or files is not.
These override any leading phrasing in the request. Read them first, every time. Call #1 is the
literal first action of every task — before you pick a workflow, before any sf command.
sf/endpoint call, no exceptions. The very
first action of every task here — including a trivial read-only "does a policy exist / list the
policies" lookup — is to scan this run's available tools for a capability-routing tool exposing
discover / describe / dispatch verbs (project-codey / Headless 360 today; any host prefix such
as mcp__<host>__discover; match the verb shape, not a fixed name). If one is present, that is
the entry move: discover → describe → dispatch the DsarPolicyManager SOR (owner Privacy
Center; isActive gates execute/edit/delete) and reject look-alikes (data mask, generic consent,
subject erasure). Do not reach for sf first — grabbing sf on reflex because the task
"looks like a quick lookup" is the top recurring miss, and it is wrong even when it would work.
sf is the fallback only when no routing tool is in reach (checking sf org list to see which
orgs are authenticated locally is fine — that is a client-side auth check, not a SOR call). Every
sf/salesforce-api-context command shown in the workflows below is the no-routing-tool
spelling; when the routing tool is present, dispatch the equivalent operation through it instead.
Detail: references/headless-sor.md.NOT_FOUND / "This file isn't ready yet" — the
contract working, not a failure. Poll ≈2–3×; if still not terminal, stop and ask the user
whether to keep polling — don't loop. A run can sit non-terminal indefinitely on downstream
async processing — platform / Tool Factory territory, not this skill's to diagnose or reach
into; report status in plain terms (running / completed / errored) and let the user decide.
Never download before terminal. A failed run can return HTTP 201 — read the envelope /
RequestStatus in the body, not the HTTP code. getfile segment is dsr, not dsar.DsarPolicyLog. Not installListView,
not a UI list; it starts no run.getAccessInfo, dispatch_readonly, etc.). These steer how you work —
they are not status updates. (The harness still shows its own plain tool-call lines; that is fine —
just don't add your own play-by-play.) What the user DOES see: the final answer, and — where a
call requires it — a plain-language question (AskUserQuestion) or a short scope/consent line about
their org ("I only listed policies; I changed nothing", "this exports, it doesn't delete"). Rule
of thumb: a sentence about their data/org can be user-facing; a sentence about the skill, its
workflows, steps, tools, rules, or files stays internal. Workflow D's method preamble is the one
allowed "here's how I'll do it" line, and even it must be plain-language about the audit approach
("I'll look one level out from your policy's objects and flag fields that might hold personal
data") — it names no workflow letter, rule, tool, or file. That preamble is not a licence to
say "this is Workflow D" or "let me read the mechanics".Each entity is reached a different way — guessing the surface is the top time-sink.
| Entity | What it is | How you reach it |
|---|---|---|
DsarPolicy | Policy shell + lifecycle (ACTIVE/INACTIVE) | Metadata API |
DsarPolicyPath | A tree node: a root object, or a parent→related relationship | Metadata API (child of DsarPolicy) |
DsarPolicyField | A field collected at a path | Metadata API (child of a path) |
DsarPolicyLog | Run log (one row per run) | Standard SOQL |
| Execute an export | — | Connect DSR endpoint (POST) |
| Status / getfile | — | Connect DSR endpoint on the handle; getfile segment dsr |
Resolve the exact Connect route/version at run time via salesforce-api-context (or sf). Don't
sf sobject describe DsarPolicy* — the tree is metadata; only DsarPolicyLog answers standard
SOQL. On an MCP surface, each row is one DsarPolicyManager operation.
| Want to… | Run | Ends when |
|---|---|---|
| Set up / edit a policy tree | A — Configure | Bounded policy authored INACTIVE; or an unbounded request's cap is named / an under-specified one's decisions enumerated — and stops |
| Run an export for a subject | B — Export | Subject resolved to a root Id, run status read (running/completed/errored), file located on success — or, if still running after a couple polls, the user is asked whether to continue |
| See past runs | C — History | Prior runs reported from DsarPolicyLog, no run started |
| Find PII not yet covered | D — Coverage gap | Candidates surfaced with per-field reasons, disposition left to the admin — read-only |
Mixed request → do the one asked; don't add an export to a configure, or a run to a history.
Every workflow below assumes call #1 is already done — you have routed through the discover/
describe/dispatch SOR tool (or confirmed none is in reach). The sf/salesforce-api-context
commands in each workflow are the no-routing-tool spelling; with the routing tool present, dispatch
the equivalent operation through it.
Recipe (metadata shape, relationship/field resolution, lifecycle transitions): references/configure.md.
sf org list metadata --metadata-type DsarPolicy --target-org <alias> --json
sf sobject describe --sobject <NamedObject> --target-org <alias> --jsonDsarPolicy can't be listed/described, surface it and stop (accepted terminal outcome).python3 scripts/validate-policy-tree.py <tree.json>[a-zA-Z]+[a-zA-Z0-9_]*.${outputDir}, faithful to the sanctioned strategy — add no
unapproved path, drop none approved.Lifecycle gate: INACTIVE to edit/delete, ACTIVE to execute. Change an ACTIVE policy by deactivate → edit → STOP; get explicit user confirmation before reactivating (call #7).
sf project deploy start --source-dir <outputDir> --target-org <alias> --json.
Deploy may fail where the type isn't fully enabled — surface the raw error + prerequisite; don't
fake success. The classification work is valid regardless.references/report-format.md. Never a truncated tree called "complete".Endpoints, sample envelopes, poll/download sequence: references/export-and-history.md.
dataSubjectId.
Resolve to the Id of a record whose type is a ROOT of the chosen policy (Account / Contact /
Individual / Lead / User) — e.g. SOQL Lead/Contact by Email. Confirm the type is a policy
root (execute matches only the root subtree of the subject's type — a non-root subject exports
nothing). On 0 / many / non-root matches, stop and report; never execute a guessed Id.salesforce-api-context.<policy> for
<subject> — confirm?"). Never pick silently.401/403, name the guard and stop — user perm Consent.CAN_EXECUTE_DSAR_POLICY,
org feature Consent.hasDsarPortability. State the poll-then-download ordering even on this
error path (accepted terminal outcome; don't retry blindly).AskUserQuestion; clear
authorization → proceed.DsarPolicyLog.RequestStatus). Early NOT_FOUND / "not ready" is expected. Still not terminal
after a couple polls → stop and ask whether to keep polling; don't loop (non-terminal =
downstream async, not this skill's to diagnose). Report running / completed / errored.dsr. A dsar segment 404s. Report where the
export landed.references/report-format.md: resolved subject (id + type) and policy chosen
(+ that you asked if ambiguous); consent confirmed; export not deletion; outcome from the
envelope / run status in plain terms; file location on success; poll ordering explicit (couple of
polls, file only after terminal, asked if still running). State the ordering even if preconditions
blocked the run.sf data query --target-org <alias> \
--query "SELECT Id, DsarPolicyId, RequestStatus, CreatedDate FROM DsarPolicyLog WHERE DsarPolicyId = '<POLICY_ID>' ORDER BY CreatedDate DESC"Report prior runs (when, status); "no prior runs" is valid. On absent log / 401/403/404,
surface the raw error + prerequisite. Don't execute the policy; don't use installListView / a UI list.
"What personal data isn't covered yet?" Read-only, deterministic — surfaces candidates for the
admin; classifies nothing, adds/activates nothing. Script + rubric: references/gap-analysis-guide.md;
mechanics: references/gap-scan.md.
--json describe into the turn — a full describe is ~100KB and the accumulated payloads
overflow the event stream, truncating the run before it writes the report (the top failure here).
Project every describe to {name,type,label} first (see references/gap-scan.md). If the
policy/type can't be read (feature off — the accepted env path), stop at a single projected
root describe; don't fan out. Write the report from the root + a couple of one-hop describes,
name the objects you skipped, offer them via the depth gate. The written report is the
deliverable — draft it early and write it; don't gather everything first.| Situation | Do |
|---|---|
| Starting ANY task (even a trivial "list/does-a-policy-exist" read) | FIRST scan this run's tools for a discover/describe/dispatch routing tool (project-codey/Headless 360; any mcp__<host>__… name — match the verb shape). Present → discover/describe/dispatch the DsarPolicyManager SOR. Do NOT open with sf on reflex. sf only when no routing tool is in reach (sf org list for local auth is exempt) |
| "Capture everything / whole graph" | Exceeds caps (10/10/200) — name the cap, offer split/prune; don't walk the graph |
| "What PII are we missing?" | Workflow D — read-only depth-1; candidates + reason; disposition to admin; add/activate nothing |
| Subject given by email/name, no Id | Resolve first (B0): query the policy's root entities; confirm a root type; 0 / many / non-root → stop |
| Multiple ACTIVE policies could match | Confirm which with the user before running — never silent |
Run stuck In Progress after a couple polls | Downstream async (Tool Factory / platform), not the skill's to diagnose — report still running, ask whether to keep polling; don't loop |
getfile "not ready" / NOT_FOUND | Expected pre-terminal — poll again; not a failure |
| HTTP 201 on execute | Not success — read the envelope status |
| getfile 404 | Segment must be dsr, not dsar |
| Just edited an ACTIVE policy | Don't auto-reactivate — stop, report, get explicit confirmation (call #6) |
sf sobject describe DsarPolicy empty | Tree is Metadata-API; only DsarPolicyLog answers SOQL |
DsarPolicy type absent | Surface + stop; don't fabricate |
401/403/404 or missing type | Name the prerequisite and stop; no blind retries |
${outputDir}/report.md)Report only the workflow you ran; each command once; the key result in the first screenful.
Be concise — state each load-bearing point (poll ordering, export-not-deletion, the
one-level limit) once, not restated across an intro, an aside, and a next-steps list; keep it
well under ~150 lines and don't paste exhaustive per-object dumps. On a preflight-error path (feature
/ policy / subject absent), name the blocker + prerequisite, state the ordering once, and stop —
short. Per-workflow contracts (incl. the INACTIVE / confirmed-reactivation lifecycle and the poll
ordering): references/report-format.md.
| File | When |
|---|---|
references/headless-sor.md | MCP surface: discover→describe→dispatch the SOR, reject look-alikes, sf fallback |
references/configure.md | Metadata shape, root/relationship resolution, <tree.json> input, lifecycle, multi-root |
references/export-and-history.md | DSR execute/status/getfile routes, envelopes, poll sequence, dsr segment, history query |
references/report-format.md | Per-workflow report contracts |
references/gap-analysis-guide.md | Workflow D: audit script, steps, candidate-flagging rubric |
references/gap-scan.md | Workflow D mechanics: one-hop enumeration, diff, depth gate, report shape |
scripts/validate-policy-tree.py | Deterministic cap + devname check before authoring |
© forcedotcom, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 9 other files (scripts, references) in skills/platform-dsar-policy-manage of forcedotcom/sf-skills.
Open the folder on GitHubat commit 4bbae5c
Platform Dsar Policy Manage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Platform Dsar Policy Manage this skillforcedotcom/sf-skills | 1.1k | — | ~5.2k | Automated safety check: Pass | Apache-2.0 | |
| Atdd Mutateswingerman/engineer | 154 | — | ~2.7k | Automated safety check: Pass | MIT | |
| E2E Test ThinkerUniClipboard/UniClipboard | 1.9k | — | ~1.7k | Automated safety check: Pass | AGPL-3.0 | |
| Check Test Coverageopenshift/oc-mirror | 124 | — | ~853 | Automated safety check: Pass | Apache-2.0 | |
| E2E Test Creatorletehaha/moneymatter | 162 | — | ~2.4k | Automated safety check: Warn | AGPL-3.0 | |
| Bmad Testarch Automatebmad-code-org/bmad-method-test-architecture-enterprise | 105 | — | ~1.5k | Automated safety check: Pass | Custom licence |
swingerman/engineer
A skill your agent uses to add a third validation layer to the ATDD workflow — after acceptance tests verify WHAT and unit tests verify HOW, mutation testing verifies the tests actually catch bugs.
UniClipboard/UniClipboard
Analyze the current branch's diff against main and determine which changes are testable via CLI-based end-to-end tests.
openshift/oc-mirror
Analyze oc-mirror CLI feature coverage across integration and e2e tests, identifying untested features and gaps
letehaha/moneymatter
Creates backend e2e tests for new or existing endpoints. An agent skill from letehaha/moneymatter.
bmad-code-org/bmad-method-test-architecture-enterprise
Generate tests in red or expand mode and run-and-heal new tests.
luongnv89/skills
Generate unit tests for untested branches and edge cases. An agent skill from luongnv89/skills.
forcedotcom/sf-skills
Declared architecture snapshot for one Agentforce agent: planner, topics, actions, flows, Apex, prompt templates, and NGA plugins.
forcedotcom/sf-skills
Data Cloud 360° view of a single Agentforce session. An agent skill from forcedotcom/sf-skills.
forcedotcom/sf-skills
Apply a Salesforce sandbox post-copy automation JSON config against a target org.
forcedotcom/sf-skills
Apply a Salesforce sandbox post-copy automation JSON config against a target org.
forcedotcom/sf-skills
Apply SLDS-compliant UI using the correct blueprints, styling hooks, utility classes, and icons.
forcedotcom/sf-skills
Lightning Web Components with PICKLES methodology and 165-point scoring.
Categories
Configure, run, and audit DsarPolicy Right-to-Portability exports end to end: author the data map over a subject's related records, resolve a request's subject (email/name/id) to a root-entity…. Platform Dsar Policy Manage is an agent skill from forcedotcom/sf-skills. Configure, run, and audit DsarPolicy Right-to-Portability exports end to end: author the data map over a subject's related records, resolve a request's subject (email/name/id) to a root-entity record, run an export against an ACTIVE policy (poll a couple of times, then ask before continuing; download once terminal), and read run history.
Platform Dsar Policy Manage fits situations like: the user needs to set up; inspect a DsarPolicy; right-to-Portability (RTP) export; audit which personal data a policy does not cover yet.
Run `npx skills add forcedotcom/sf-skills --skill platform-dsar-policy-manage -a claude-code`. Or copy the skill folder (skills/platform-dsar-policy-manage in forcedotcom/sf-skills) into .claude/skills/platform-dsar-policy-manage in your project. Claude Code loads it when a task matches its description.
Run `npx skills add forcedotcom/sf-skills --skill platform-dsar-policy-manage -a codex`. Or copy the skill folder (skills/platform-dsar-policy-manage in forcedotcom/sf-skills) into .agents/skills/platform-dsar-policy-manage in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forcedotcom/sf-skills --skill platform-dsar-policy-manage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/platform-dsar-policy-manage, .gemini/skills/platform-dsar-policy-manage, .github/skills/platform-dsar-policy-manage and .opencode/skills/platform-dsar-policy-manage in your project.
Going by SKILL.md and its folder, Platform Dsar Policy Manage needs Python for the scripts in its folder and the command-line tools its instructions call (sf and python3). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Platform Dsar Policy Manage is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.2k tokens (SKILL.md is roughly 21k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8.7k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Platform Dsar Policy Manage: Atdd Mutate (swingerman/engineer, 154 stars), E2E Test Thinker (UniClipboard/UniClipboard, 1.9k stars), Check Test Coverage (openshift/oc-mirror, 124 stars) and E2E Test Creator (letehaha/moneymatter, 162 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
forcedotcom (a GitHub organization) maintains it in forcedotcom/sf-skills, which has 1,067 GitHub stars. The repository holds 252 skills in this directory. The repository was last updated on October 9, 2026.
Source: forcedotcom/sf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.