Soql Lib Query Builder
beyond-the-cloud-dev/soql-lib
Builds Salesforce SOQL queries using the SOQL Lib fluent builder API (SOQL.cls).
Configure Salesforce Shield Platform Encryption — generate deployable encryption settings and encrypted-field metadata, and answer key-model and lifecycle questions.
$ npx skills add forcedotcom/sf-skills --skill platform-encryption-configure -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install forcedotcom/sf-skills platform-encryption-configure --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/platform-encryption-configure .claude/skills/platform-encryption-configure && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "platform-encryption-configure" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/platform-encryption-configure into .claude/skills/platform-encryption-configure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "platform-encryption-configure", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/forcedotcom/sf-skills/tree/main/skills/platform-encryption-configureType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add forcedotcom/sf-skills --skill platform-encryption-configure -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install forcedotcom/sf-skills platform-encryption-configure --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/platform-encryption-configure .agents/skills/platform-encryption-configure && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "platform-encryption-configure" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/platform-encryption-configure into .agents/skills/platform-encryption-configure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "platform-encryption-configure", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forcedotcom/sf-skills --skill platform-encryption-configure -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install forcedotcom/sf-skills platform-encryption-configure --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/platform-encryption-configure .cursor/skills/platform-encryption-configure && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "platform-encryption-configure" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/platform-encryption-configure into .cursor/skills/platform-encryption-configure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "platform-encryption-configure", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/forcedotcom/sf-skills.git --path skills/platform-encryption-configure--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add forcedotcom/sf-skills --skill platform-encryption-configure -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install forcedotcom/sf-skills platform-encryption-configure --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/platform-encryption-configure .gemini/skills/platform-encryption-configure && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "platform-encryption-configure" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/platform-encryption-configure into .gemini/skills/platform-encryption-configure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "platform-encryption-configure", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install forcedotcom/sf-skills platform-encryption-configureInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add forcedotcom/sf-skills --skill platform-encryption-configure -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/platform-encryption-configure .github/skills/platform-encryption-configure && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "platform-encryption-configure" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/platform-encryption-configure into .github/skills/platform-encryption-configure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "platform-encryption-configure", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forcedotcom/sf-skills --skill platform-encryption-configure -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install forcedotcom/sf-skills platform-encryption-configure --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/platform-encryption-configure .opencode/skills/platform-encryption-configure && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "platform-encryption-configure" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/platform-encryption-configure into .opencode/skills/platform-encryption-configure/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "platform-encryption-configure", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
platform-encryption-configureConfigure Salesforce Shield Platform Encryption — generate deployable encryption settings and encrypted-field metadata, and answer key-model and lifecycle questions.
Platform Encryption Configure is an agent skill from forcedotcom/sf-skills. Configure Salesforce Shield Platform Encryption — generate deployable encryption settings and encrypted-field metadata, and answer key-model and lifecycle questions. TRIGGER when: user wants to turn on deterministic encryption, encrypt a field, set up Cache-Only Keys, External Key Management, or replay detection, or mentions Shield Platform Encryption, encryption at rest, deterministic vs probabilistic encryption, encryptionScheme, PlatformEncryptionSettings, EncryptionKeySettings, BYOK, BYOKMS, tenant secrets…
Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 12 other files, including scripts, reference files and assets (for example `references/encryption-schemes.md`, `references/key-models.md` and `references/tenant-secret-lifecycle.md`).
It sits in Sales & Support, covering Cryptography and CRM management. It works with Salesforce. The repository describes itself as: Salesforce's curated collection of agent skills for building applications. Optimized for Agentforce Vibes, compatible with all AI tools. The licence is Apache-2.0.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit e5164d9. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Shell), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Platform Encryption Configure loads about 4.1k tokens when it runs, and up to ~5.8k if it reads all its reference files. Until then it costs about 256 tokens; SKILL.md has 1,847 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from forcedotcom/sf-skills at commit e5164d9, republished under its Apache-2.0 licence (© forcedotcom). 1,847 words, ~4,072 tokens.
.claude/skills/platform-encryption-configure/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.Configures Salesforce Shield Platform Encryption by generating the metadata that turns it on and choosing the right settings: which encryption scheme a field should use, which key-management model fits a requirement, and how the tenant-secret lifecycle works. This is a hybrid skill — it emits deployable *.settings-meta.xml / *.field-meta.xml where Platform Encryption exposes a real Metadata API surface, and returns grounded guidance where the operation is UI/REST-only.
encryptionScheme on a field; enabling deterministic encryption, Cache-Only Keys, External Key Management, and replay detection via PlatformEncryptionSettings / EncryptionKeySettings; explaining BYOK / BYOKMS / EKM / Cache-Only key models; tenant-secret rotation and destruction semantics; the query behavior of encrypted fields.platform-custom-field-generate); the raw Metadata API field reference (use platform-metadata-api-context-get); Classic Encryption (EncryptedText fields) — that is a separate, legacy feature; deploying/pushing metadata to an org (that belongs to a deploy lifecycle skill).Gather or infer before proceeding:
assets/. Guidance → answer from references/. A question is guidance whenever the ask is to explain, confirm, or compare — "is that right?", "what's the relationship?", "can we…?", "is there an ordering requirement?", "explain the difference between X and Y", "which key model should we use?" — even if the user also says they are about to write, deploy, or author settings themselves. The user writing settings is their action; it does not make the skill's deliverable a file. Only an explicit "generate / create / give me the file / here is my field, encrypt it" is an artifact request.*.settings-meta.xml. Naming the enabling setting in that answer (e.g. canExternalKeyManagement, enableCacheOnlyKeys) does NOT turn it into a settings artifact — cite the field name inline in the answer file; do not emit an EncryptionKey.settings-meta.xml unless the user explicitly says "generate/create the settings file."If the request is clear, generate or answer immediately — do not interrogate the user.
Classify the request — deployable artifact vs guidance, using the Required Inputs above. Then scope the output to exactly what was asked:
answer.md) containing the full written diagnosis/explanation — and nothing else. Do not also emit a *.settings-meta.xml, a *.field-meta.xml, or a second helper doc. This covers every "what happens when…?", "how do I…?", "which model…?", "is X right…?", "can we…?", "what's the relationship / ordering…?" question, including query-behavior and Cache-Only/replay questions. A clause like "before I write our settings" or "before I author the file" describes the user's next step and does NOT turn the question into a deployable-metadata request — write the answer file, not a settings file.Deterministic* scheme and enable enableDeterministicEncryption", or "use External Key Management — canExternalKeyManagement"). Do not additionally materialize a *.field-meta.xml or *.settings-meta.xml to demonstrate that change — mentioning the element in the answer is the complete deliverable. Produce a deployable metadata file only when the user explicitly says generate/create/give me the field or settings file.DEPLOYMENT_GUIDE.md, README.md, an EXPLANATION.md, an org-settings file, or any companion artifact the user did not ask for.For field encryption — read references/encryption-schemes.md to choose the scheme, then load assets/encrypted-field.field-meta.xml as the starting template. Set encryptionScheme to exactly one of the four valid enum values (see the reference). Only Deterministic* schemes are filterable.
Write the field file at the SFDX source path, not the root. A
*.field-meta.xmlmust live atobjects/<ObjectApiName>/fields/<FieldApiName>__c.field-meta.xml(e.g.objects/Patient__c/fields/Diagnosis_Notes__c.field-meta.xml) — the object folder uses the object's API name (Patient__cfor a custom object,Contactfor a standard one) and the file is named after the field API name. Emitting the file at the repo root, in a flat directory, or under any other folder is a structural miss even when the XML itself is correct.
For org-level encryption settings — load assets/PlatformEncryption.settings-meta.xml (deterministic encryption, field-history encryption, MEK permission) or assets/EncryptionKey.settings-meta.xml (Cache-Only, EKM, Data 360, transactional DB, replay detection). Read references/key-models.md before setting any key-model field.
Name the output file after the Settings member, not the root element, and write it under
settings/. ASettingsfile must besettings/<member>.settings-meta.xml, where<member>is the org's metadata member name —EncryptionKey(root<EncryptionKeySettings>) andPlatformEncryption(root<PlatformEncryptionSettings>). Put it in thesettings/source folder (e.g.settings/EncryptionKey.settings-meta.xml), not the repo root. Naming the key-settings fileEncryption.settings-meta.xmlorEncryptionKeySettings.settings-meta.xmlfails deployment with "The object '…' of type Settings metadata does not exist."
Cache-Only Keys and replay detection are a one-way dependency, not an auto-enable. You may set
enableReplayDetectiononly afterenableCacheOnlyKeysistrue; enabling Cache-Only does not turn replay detection on by itself. An org can validly run Cache-Only with replay detection off.
For tenant-secret operations (rotate, destroy, BYOK upload, Cache-Only callout setup) — read references/tenant-secret-lifecycle.md. These are UI/REST-only; capture the guidance in the single markdown answer file, not a deployable metadata file.
Validate any generated settings XML — run scripts/validate-encryption-metadata.sh with the file path as its argument, and fix anything it reports. It checks the replay-detection dependency and the encryptionScheme enum deterministically.
Compare against the worked example — verify a generated EncryptionKeySettings file against examples/cache-only-keys.settings-meta.xml.
| Constraint | Rationale |
|---|---|
encryptionScheme must be exactly one of CaseInsensitiveDeterministicEncryption, CaseSensitiveDeterministicEncryption, None, ProbabilisticEncryption | These are the only values the Metadata API accepts (CustomField, API 44.0+); any other string fails deployment. |
Set enableReplayDetection only when enableCacheOnlyKeys is true | The contract is "Requires enableCacheOnlyKeys=true before setting enableReplayDetection to true" — a one-way dependency. |
| Use deterministic schemes only when the field must be filtered, sorted, or grouped | Probabilistic is stronger but non-filterable; deterministic trades some cryptographic strength for queryability. |
| Never claim a filter/sort/group on a probabilistically-encrypted field silently returns zero rows | The platform rejects the query with INVALID_FIELD (see gotchas); telling the user it "returns nothing" is factually wrong. |
Do not emit enableExternalKeyManagement — the field is canExternalKeyManagement | The WSDL element is canExternalKeyManagement; the sample in some docs uses a non-existent element name. |
| Transactional-DB, EKM, and Data 360 key fields require API 63.0+ | canEncryptTransactionalDatabase, canExternalKeyManagement, canManageDataCloudKeys were introduced in 63.0. |
A guidance question produces exactly one markdown answer file — never a deployable *.settings-meta.xml / *.field-meta.xml, and never a second doc | The answer file is the user's reference document — it persists in the workspace and can be shared or revised. Emitting a deployable metadata file for a guidance question is unsolicited configuration that could be accidentally applied; emitting no file leaves the user without a tangible deliverable. |
| An artifact request emits only the metadata file(s) asked for — no companion files | Adding a DEPLOYMENT_GUIDE.md/README.md/EXPLANATION.md or an extra settings file the user didn't request is noise. Prerequisites belong in a code comment inside the artifact, not a second file. |
| Issue | Resolution |
|---|---|
| Filtering/sorting/grouping on a probabilistically-encrypted field | The query is rejected with INVALID_FIELD: "field '<Name>' can not be sorted / filtered / grouped in a query call." Switch the field to a deterministic scheme if queryability is required. |
| Assuming Cache-Only Keys auto-enables replay detection | It does not. Set enableReplayDetection explicitly, and only after enableCacheOnlyKeys=true. |
| Case sensitivity in deterministic matching | CaseSensitiveDeterministicEncryption matches exact case; CaseInsensitiveDeterministicEncryption normalizes case. Choosing wrong silently breaks equality filters. |
| Confusing BYOK with BYOKMS/EKM | BYOK = you upload key material Salesforce stores; BYOKMS/EKM = key material stays in your external KMS. See references/key-models.md. |
Using enableExternalKeyManagement element name | Wrong element. The field is canExternalKeyManagement. |
| Classic Encryption vs Shield | encryptionScheme is Shield only. EncryptedText custom fields are the legacy Classic feature and out of scope. |
Deliverables depend on the request — produce exactly these and nothing more:
answer.md) that fully captures the diagnosis/explanation. Do not additionally emit a deployable *.settings-meta.xml / *.field-meta.xml or a second doc, and do not answer with no file at all — the answer file is the user's persistent reference document.*.field-meta.xml with encryptionScheme set, written at objects/<ObjectApiName>/fields/<FieldApiName>__c.field-meta.xml. Not a settings file, not a deploy guide. Pick <type> to match the request: Text for a string field up to 255 chars; LongTextArea only when the field must exceed 255 chars (256+). "Long text … up to 255 characters" is a Text field, not LongTextArea. Strip the template's instructional comment block from the delivered file — ship clean metadata. Keep the accompanying chat prose tight — one or two sentences naming the scheme chosen and why (e.g. "ProbabilisticEncryption — strongest at-rest protection; the field can't be filtered/sorted/grouped, which matches your no-query requirement"). Do not restate the whole prompt, enumerate every scheme, or add setup/deployment walkthroughs; the deliverable is the file, not an essay.settings/<member>.settings-meta.xml named after its Metadata API member — settings/PlatformEncryption.settings-meta.xml (root <PlatformEncryptionSettings>) and/or settings/EncryptionKey.settings-meta.xml (root <EncryptionKeySettings>). Do not name the file after the root element, and do not drop it at the repo root.Do not add companion files (DEPLOYMENT_GUIDE.md, README.md, an extra org-settings file) that the user did not ask for — state prerequisites in a code comment inside the artifact, or inside the single answer file for guidance. File structure follows the templates in assets/.
| Need | Delegate to |
|---|---|
| A custom field with no encryption | platform-custom-field-generate |
| The raw Metadata API type/field reference | platform-metadata-api-context-get |
| File | When to read |
|---|---|
assets/encrypted-field.field-meta.xml | Before generating an encrypted custom field |
assets/PlatformEncryption.settings-meta.xml | Before generating org encryption-policy settings (member PlatformEncryption) |
assets/EncryptionKey.settings-meta.xml | Before generating key-management settings — Cache-Only, EKM, Data 360 (member EncryptionKey) |
references/encryption-schemes.md | When choosing deterministic vs probabilistic, or explaining encrypted-field query behavior |
references/key-models.md | When configuring or explaining BYOK / BYOKMS / EKM / Cache-Only key models |
references/tenant-secret-lifecycle.md | When the user asks about key rotation, destruction, or BYOK upload |
examples/cache-only-keys.settings-meta.xml | To verify a generated Cache-Only key-settings file |
scripts/validate-encryption-metadata.sh | After generating any settings XML — validates the replay dependency and scheme enum |
© forcedotcom, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 8 other files (scripts, references, assets) in skills/platform-encryption-configure of forcedotcom/sf-skills.
Open the folder on GitHubat commit e5164d9
Platform Encryption Configure next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Platform Encryption Configure this skillforcedotcom/sf-skills | 1.1k | — | ~4.1k | Automated safety check: Pass | Apache-2.0 | |
| Soql Lib Query Builderbeyond-the-cloud-dev/soql-lib | 154 | — | ~4.3k | Automated safety check: Pass | MIT | |
| Sf DatacloudJaganpro/sf-skills | 424 | — | ~2.7k | Automated safety check: Pass | MIT | |
| Soql Lib Selectorbeyond-the-cloud-dev/soql-lib | 154 | — | ~2k | Automated safety check: Pass | MIT | |
| Dev SetupPortwood-Global-Solutions/Portwood | 125 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | |
| Sf FlowJaganpro/sf-skills | 424 | — | ~1.8k | Automated safety check: Pass | MIT |
beyond-the-cloud-dev/soql-lib
Builds Salesforce SOQL queries using the SOQL Lib fluent builder API (SOQL.cls).
Jaganpro/sf-skills
Salesforce Data Cloud product orchestrator for connect→prepare→harmonize→segment→act workflows.
beyond-the-cloud-dev/soql-lib
Creates Salesforce Apex selector classes using the SOQL Lib selector pattern.
Portwood-Global-Solutions/Portwood
Get from a fresh clone of Portwood to a working, fully-tested Salesforce org.
Jaganpro/sf-skills
Creates and validates Salesforce Flows with 110-point scoring.
gmapsscraper/google-maps-agent-skills
Export Google Maps business data to CSV, JSON, or CRM format (HubSpot, Pipedrive, Salesforce).
forcedotcom/sf-skills
Declared architecture snapshot for one Agentforce agent: planner, topics, actions, flows, Apex, prompt templates, and NGA plugins.
forcedotcom/sf-skills
Data Cloud 360° view of a single Agentforce session. An agent skill from forcedotcom/sf-skills.
forcedotcom/sf-skills
Apply a Salesforce sandbox post-copy automation JSON config against a target org.
forcedotcom/sf-skills
Apply a Salesforce sandbox post-copy automation JSON config against a target org.
forcedotcom/sf-skills
Apply SLDS-compliant UI using the correct blueprints, styling hooks, utility classes, and icons.
forcedotcom/sf-skills
Lightning Web Components with PICKLES methodology and 165-point scoring.
Works with
Categories
Configure Salesforce Shield Platform Encryption — generate deployable encryption settings and encrypted-field metadata, and answer key-model and lifecycle questions. Platform Encryption Configure is an agent skill from forcedotcom/sf-skills. Configure Salesforce Shield Platform Encryption — generate deployable encryption settings and encrypted-field metadata, and answer key-model and lifecycle questions.
Platform Encryption Configure fits situations like: : user wants to turn on deterministic encryption; encrypt a field; set up Cache-Only Keys; external Key Management.
Run `npx skills add forcedotcom/sf-skills --skill platform-encryption-configure -a claude-code`. Or copy the skill folder (skills/platform-encryption-configure in forcedotcom/sf-skills) into .claude/skills/platform-encryption-configure in your project. Claude Code loads it when a task matches its description.
Run `npx skills add forcedotcom/sf-skills --skill platform-encryption-configure -a codex`. Or copy the skill folder (skills/platform-encryption-configure in forcedotcom/sf-skills) into .agents/skills/platform-encryption-configure in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forcedotcom/sf-skills --skill platform-encryption-configure -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/platform-encryption-configure, .gemini/skills/platform-encryption-configure, .github/skills/platform-encryption-configure and .opencode/skills/platform-encryption-configure in your project.
Going by SKILL.md and its folder, Platform Encryption Configure needs a shell for the scripts in its folder. Our summary lists: A Bash shell.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Platform Encryption Configure is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.1k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.7k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Platform Encryption Configure: Soql Lib Query Builder (beyond-the-cloud-dev/soql-lib, 154 stars), Sf Datacloud (Jaganpro/sf-skills, 424 stars), Soql Lib Selector (beyond-the-cloud-dev/soql-lib, 154 stars) and Dev Setup (Portwood-Global-Solutions/Portwood, 125 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
forcedotcom (a GitHub organization) maintains it in forcedotcom/sf-skills, which has 1,060 GitHub stars. The repository holds 251 skills in this directory. The repository was last updated on October 7, 2026.
Source: forcedotcom/sf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.