Agent skill

Platform Widget Generate

by forcedotcom in forcedotcom/sf-skills

A skill your agent uses to author a complete HXL WidgetBundle (UEM body + schema.json + -meta.xml).

Apache-2.0Auto-check passed

Install Platform Widget Generate

skills CLI
$ npx skills add forcedotcom/sf-skills --skill platform-widget-generate -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install forcedotcom/sf-skills platform-widget-generate --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/platform-widget-generate .claude/skills/platform-widget-generate && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
platform-widget-generate
GitHub stars
1.1k
Token cost
~5.8k tokens
SKILL.md length
2,107 words
Files
9 (incl. references)
Skills in repo
248
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses to author a complete HXL WidgetBundle (UEM body + schema.json + -meta.xml).

  • Works in 2 steps: lightningTypeSchema — { path,… → Extracted from the user's prompt — when…
  • Author a complete HXL WidgetBundle (UEM body + schema.json + -meta.xml)
  • SKILL.md covers When to Use This Skill, Inputs, Output and Composition, plus 9 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Platform Widget Generate is an agent skill from forcedotcom/sf-skills. Use this skill to author a complete HXL WidgetBundle (UEM body + schema.json + -meta.xml). TRIGGER when: user asks for a widget, mosaic, fragment, card, or rich UI surface for any subject, domain, feature, or entity noun; the prompt names only an entity or data shape without invoking Lightning Types, CLTs, or Apex-backed types. DO NOT TRIGGER when: the prompt explicitly says 'Lightning Type', 'CLT', 'Custom Lightning Type', 'Apex-backed type', or references '@apexClassType/...' (use…

Its SKILL.md is about 5.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including reference files (for example `examples/conditional.json`, `examples/formulas.json` and `examples/list-with-foreach.json`).

The repository describes itself as: Salesforce's curated collection of agent skills for building applications. Optimized for Agentforce Vibes, compatible with all AI tools. The licence is Apache-2.0.

When your agent uses it

  • Author a complete HXL WidgetBundle (UEM body + schema.json + -meta.xml)
  • : user asks for a widget
  • Rich UI surface for any subject
  • The prompt names only an entity

Example prompts

  • “Lightning Type”
  • “Custom Lightning Type”
  • “Apex-backed type”
  • “/platform-widget-generate”

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. lightningTypeSchema — { path, apexClassFqn } for an existing Apex-backed Lightning Type. The FQN takes one of two forms: outer-class ()…
  2. Extracted from the user's prompt — when no lightningTypeSchema is passed, infer the shape directly from what the user wrote: a pasted JSON…

What it can do on your machine

Read from SKILL.md and the folder at commit 3c15867. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json and typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Platform Widget Generate loads about 5.8k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 174 tokens; SKILL.md has 2,107 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~174
When it runs · the whole SKILL.md, loaded when a task matches
~5.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~12k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from forcedotcom/sf-skills at commit 3c15867, republished under its Apache-2.0 licence (© forcedotcom). 2,107 words, ~5,757 tokens.

Download SKILL.mdSave it as .claude/skills/platform-widget-generate/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
platform-widget-generate
description
Use this skill to author a complete HXL WidgetBundle (UEM body + schema.json + -meta.xml). TRIGGER when: user asks for a widget, mosaic, fragment, card, or rich UI surface for any subject, domain, feature, or entity noun; the prompt names only an entity or data shape without invoking Lightning Types, CLTs, or Apex-backed types. DO NOT TRIGGER when: the prompt explicitly says 'Lightning Type', 'CLT', 'Custom Lightning Type', 'Apex-backed type', or references '@apexClassType/...' (use platform-lightning-type-widget-coordinate); authoring a custom-LWC renderer for a Custom Lightning Type (use platform-custom-lightning-type-generate); or editing only an LWC component.
metadata.version
1.4
metadata.domains
Platform, Agentforce
metadata.minApiVersion
68.0
metadata.relatedSkills
platform-apex-generate, platform-custom-lightning-type-generate, platform-lightning-type-widget-coordinate

Generating a Widget Bundle

Author a complete WidgetBundle: a UEM tree (tile/widget), a JSON Schema describing the widget's input contract, and the .uiwidget-meta.xml that registers the bundle.

When to Use This Skill

Use when the user asks for a widget, mosaic, fragment, or card-style rich UI surface. Do not use this skill for custom-LWC renderers or for renderer.json files inside a Custom Lightning Type bundle — those belong to platform-custom-lightning-type-generate.

Inputs

  • widgetName (required) — camelCase identifier; becomes the directory name under uiWidgets/.
  • A shape — what data the widget renders. The widget cannot be generated without it. The shape arrives one of two ways, in priority order:
    1. lightningTypeSchema — { path, apexClassFqn } for an existing Apex-backed Lightning Type. The FQN takes one of two forms: outer-class (<namespace>__<ClassName>) where the outer class is the payload, or inner-class (<namespace>__<ClassName>$<InnerClass>) where the named inner class is the payload. Passed in by the platform-lightning-type-widget-coordinate orchestrator. When present, derive per references/schema-from-lightning-type.md.
    2. Extracted from the user's prompt — when no lightningTypeSchema is passed, infer the shape directly from what the user wrote: a pasted JSON payload, an enumerated field list ("id as string, total as number"), or descriptive prose. The output is the same ordered list of { name, type, required } either way.

If neither source yields a shape, STOP and ask the user before proceeding.

Output

Three files in <pkgDir>/uiWidgets/<widgetName>/:

FileContent
<widgetName>.jsonWidget envelope — { "type": "lightning__agentforceWidget", "contentBody": { "widgetBody": { UEM tree rooted at tile/widget } } }
schema.jsonJSON Schema — root has type: "object" + properties.attributes wrapper carrying lightning:type: "lightning__objectType" and the field properties
<widgetName>.uiwidget-meta.xml<UiWidgetBundle> element with <masterLabel>, <description>, and <widgetType>JSON</widgetType>

See references/widget-bundle-layout.md for the <pkgDir> resolution procedure and the exact <widgetName>.uiwidget-meta.xml shape.


Composition

A widget body is a UEM tree of blocks nested under contentBody.widgetBody. The root node is tile/widget. Every node — root and non-root — has the same shape: no type key; just definition, optional attributes, optional meta, and optional children. Block shape:

ts
interface Block {
  definition: string  // {namespace}/{blockName} — root is "tile/widget"
  attributes?: Record<string, any>
  meta?: { // see references/widget-meta-directives.md
    forEach?: string
    forItem?: string
    if?: string
  }
  children?: Block[]
}

The first child of tile/widget.children SHOULD be a single tile/column. All widget content typically goes inside that first child for predictable vertical structure across surfaces.


Available Metadata Actions

discoverUiComponents

Purpose: Discover the palette of blocks available for composition.

Required parameters: actionName: "discoverUiComponents", metadataType: "FRAGMENT", parameters.pageType: "FRAGMENT". Optional: searchQuery to filter by name/description.

Returns: list of { definition, description, label, attributes? }.

getUiComponentSchemas

Purpose: Fetch JSON schemas (property types, required vs optional, validation) for selected blocks.

Required parameters: actionName: "getUiComponentSchemas", metadataType: "FRAGMENT", parameters.pageType: "FRAGMENT", parameters.componentDefinitions: ["namespace/definition", ...]. Optional: includeKnowledge (default true).

Returns: componentSchemas[] — success entries carry the JSON schema, failure entries carry an error message. Partial failures are supported.

Never pass tile/widget to getUiComponentSchemas — it is a fixed wrapper, not a queryable component.


Attribute Binding

  • Bind a block property to runtime data with {!$attrs.<attrName>}. <attrName> MUST match a property name in schema.json.
  • Inside a forEach, reference the loop variable instead — e.g. "text": "{!$item.name}". See references/widget-meta-directives.md.
  • A binding may be a formula expression instead of a bare field reference. See references/widget-formulas.md for the full supported-function list, syntax, and gotchas.

Actions

tile/button supports an actions attribute that dispatches an action node on an event. Two action definitions are supported:

ActionTimingRequired attributesEffect
action/openLinksynchronousurl (string). Optional target (_blank|_self, default _blank)Opens a URL
action/sendMessageasynchronouscontent (string)Posts a new user message back to the agent and earns a fresh turn
json
{
  "definition": "tile/button",
  "attributes": {
    "label": "Button Label",
    "variant": "primary",
    "actions": { "click": [ { "definition": "action/sendMessage", "attributes": { "content": "content" } } ] }
  }
}
json
{
   "definition": "tile/button",
   "attributes": {
      "label": "Button Label",
      "variant": "primary",
      "actions": { "click": [ { "definition": "action/openLink", "attributes": { "url": "https://www.example.com", "target": "_blank" } } ] }
   }
}

A tile/button with no actions attribute renders disabled — a button exists to trigger an action, so always attach a click action to a button meant to be interactive.


Layout Best Practices

These conventions cover widget structure — how blocks are grouped and stacked.

PrimitivePurposeWhen to use
tile/columnVertical stack of childrenRoot wrapper, and any group of blocks that should stack
tile/rowHorizontal stack of childrenTwo or more blocks that belong on the same line
tile/spacerWhitespace between blocksWhen extra space is needed between content groups
  • Nesting: Prefer flat layouts. Only nest a tile/column inside a tile/row (or vice versa) when the visual orientation actually changes for that subgroup.
  • Authoritative palette: the table above lists typical layout primitives. Always confirm a block exists by inspecting discoverUiComponents output — do not assume a block name from this table without seeing it in the discovery response.

Styling Best Practices

Widgets express intent, not pixels. Each surface provides a default look and feel; brand/theme overrides apply automatically.

  • Style semantically. Use variant, size, and other enum-typed attributes (primary, destructive, success, warning). Do not pin literal colors or pixel values.
  • One primary action per visible group. At most one tile/button with variant: primary. Use secondary or destructive for additional actions (see the tile/button schema for the full variant enum).
  • Every tile/button needs a click action. See Actions above — an action-less button renders disabled.
  • One h1 per widget. Use h2/h3 for sub-section headings, body for prose, caption for helper text.
  • Use semantic state variants on state-bearing blocks (tile/badge, tile/callout).
  • Accept schema defaults for gap, size unless there is a specific reason to override.
  • Don't pin width unless a content constraint requires it.
  • Use the Lucide icon set. Pass the Lucide name ("check", "alert-circle"); other icon libraries are not supported.

Workflow

  1. Resolve the widget spec — an ordered list of { name, type, required }. Source depends on which input was provided (see Inputs):

    • If lightningTypeSchema was passed by the orchestrator → derive per references/schema-from-lightning-type.md.
    • Otherwise → infer the list directly from the user prompt (pasted JSON payload, enumerated field list, or descriptive prose).
  2. Discover blocks (REQUIRED — do NOT skip). Call the discoverUiComponents metadata action via execute_metadata_action. Use property types from the widget spec to seed searchQuery (text → "text", number → "number"). If discoverUiComponents returns success: false, an error, or an empty list, STOP and surface the error verbatim — do not improvise block names from memory, prior runs, or training data. Re-run discover with a different searchQuery only if the failure is search-query-specific.

  3. Select blocks. Choose one block per widget-spec property, plus structural primitives from Layout Best Practices.

  4. Get block schemas (REQUIRED — do NOT skip). Call the getUiComponentSchemas metadata action via execute_metadata_action for the selected blocks. Review property metadata. If componentSchemas returns all-failure or empty, STOP and surface the error — do not improvise from existing widgets in the project.

  5. Build the UEM tree (example reads REQUIRED — do NOT skip). First, identify which patterns match the widget spec and read each matching example file from this skill's own examples/ directory (<skill-root>/examples/):

    Pattern in the specExample to read
    Single object (no iteration)<skill-root>/examples/single-object.json
    Any list iteration (root-level array, nested list, or list embedded in a single-object widget)<skill-root>/examples/list-with-foreach.json
    Conditional rendering (if bound to a boolean or formula)<skill-root>/examples/conditional.json
    Computed values, text/number transforms, or if driven by a formula (not a bare boolean field)<skill-root>/examples/formulas.json

    A spec may match multiple patterns (e.g. a list of items where some items render conditionally reads both list-with-foreach.json and conditional.json). Read every matching example, and only those — do not skip the read because the pattern feels familiar.

    Before writing any formula, read references/widget-formulas.md in full — it is the authoritative list of supported operators and functions; do not improvise a function name or operator that isn't documented there.

    Then:

    • Map each widget-spec property to a block property; preserve spec order.
    • Decide root iteration: single object → properties directly under root tile/column. Collection → wrap repeating block in forEach/forItem. See references/widget-meta-directives.md.
    • Bind values with {!$attrs.X} (or {!$item.X} inside forEach).
    • For conditional blocks, add "if" on meta — either a bare lightning__booleanType property, or a formula expression that evaluates to boolean. See references/widget-formulas.md.
    • When the widget spec calls for a computed value (a total, a derived label, a formatted string) rather than a raw field, express it as a formula inside {!...} per references/widget-formulas.md — do not invent a new schema property to hold a value that can be computed from existing ones.
  6. Author schema.json. Build the JSON Schema from the widget spec. Fields live one level deep under an attributes wrapper:

    json
    {
      "title": "<Widget Display Name>",
      "description": "<one line about what the widget shows>",
      "type": "object",
      "properties": {
        "attributes": {
          "lightning:type": "lightning__objectType",
          "properties": {
            "<propertyName>": {
              "title": "<label>",
              "description": "<short description>",
              "lightning:type": "<lightning__textType | lightning__numberType | ...>"
            }
          }
        }
      }
    }

    Required root keys: title, type: "object", properties.attributes (with lightning:type: "lightning__objectType" and a nested properties map). See references/schema-from-lightning-type.md for full primitive type guidance.

  7. Author <widgetName>.uiwidget-meta.xml. See references/widget-bundle-layout.md for the exact shape.

  8. Resolve <pkgDir> and write the bundle. Follow the procedure in references/widget-bundle-layout.md (## Resolving <pkgDir>). A widget bundle is a three-file set — all three files must be written in the same step; a bundle with fewer than three files is incomplete and will not deploy.

    text
    <pkgDir>/uiWidgets/<widgetName>/<widgetName>.json               # widget envelope — UEM tree (primary artifact)
    <pkgDir>/uiWidgets/<widgetName>/schema.json                     # attribute contract for the envelope
    <pkgDir>/uiWidgets/<widgetName>/<widgetName>.uiwidget-meta.xml  # UiWidgetBundle registration

    Each file has a distinct role:

    • <widgetName>.json — the widget envelope with the tile/widget UEM tree. This is the primary artifact; schema.json is its companion contract, not a substitute.
    • schema.json — the JSON Schema for the attributes referenced by {!$attrs.X} bindings in the envelope.
    • <widgetName>.uiwidget-meta.xml — the UiWidgetBundle element that registers the bundle for source tracking and deployment.

    Write all three before proceeding to self-validation.

  9. Self-validate. Before reporting, confirm each check below and report each result individually (pass or fail (<reason>)). Do not summarize as a single "all passed" line — list every check so a reviewer can spot a silent skip.

    • schema-parses — <pkgDir>/uiWidgets/<widgetName>/schema.json parses as JSON.
    • schema-root-keys — root has title (string), type: "object", and properties.attributes (object) — where properties.attributes carries lightning:type: "lightning__objectType" and a nested properties map. No unevaluatedProperties: false.
    • schema-leaf-types — every leaf under properties.attributes.properties carries a lightning:type. Singular nested inner-class fields carry lightning:type set to the inner Apex class reference (@apexClassType/<namespace>__<OuterClass>$<InnerClass>); the nested shape is not redeclared. List<InnerClass> fields carry lightning:type: "lightning__listType" with items.lightning:type set to the inner Apex class reference (@apexClassType/<namespace>__<OuterClass>$<InnerClass>), not a redeclared field map — see references/schema-from-lightning-type.md. When the list has no Apex-backed type (schema inferred from the prompt), items.lightning:type: "lightning__objectType" MUST carry an inline nested properties map for every item field the body binds via {!$item.X}.
    • bindings-resolve — every {!$attrs.X} (or {!$attrs.<outerField>.<innerField>} for nested objects) in <widgetName>.json resolves to a property under schema.json properties.attributes.properties, and every {!$item.X} resolves to a forItem loop variable defined upstream. This applies to $attrs/$item references inside formula expressions too.
    • formulas-supported — every function name used inside a {!...} expression appears in the Supported functions list in references/widget-formulas.md.
    • body-envelope — <widgetName>.json root has type: "lightning__agentforceWidget" and a contentBody object whose widgetBody carries the UEM tree rooted at tile/widget. No node in the tree — root or non-root — carries a type key.
    • metaxml-wellformed — <widgetName>.uiwidget-meta.xml parses as well-formed XML.
    • metaxml-elements — <widgetName>.uiwidget-meta.xml has root <UiWidgetBundle> and contains <masterLabel> (non-empty), <description> (non-empty), and <widgetType>JSON</widgetType>.
    • files-present — all three files exist at the resolved <pkgDir>/uiWidgets/<widgetName>/ path.
    • button-actions-present — every tile/button in <widgetName>.json has an actions.click action node whose definition is action/openLink or action/sendMessage.
Show full SKILL.md (404 more words)Show less

Rules / Constraints

ConstraintRationale
Block definitions follow {namespace}/{blockName} and must match discoverUiComponents outputRuntime resolves blocks by exact definition string
Never pass tile/widget to getUiComponentSchemasIt is a fixed wrapper, not a queryable component
Always supply parameters (with required keys) when calling execute_metadata_actionMissing parameters cause hard failure, not partial result
Every {!$attrs.X} in the body resolves to a property in the widget schema.jsonNo invented fields
Every tile/button carries an actions.click entry using action/openLink or action/sendMessage onlyThese are the only two supported tile action definitions; an action-less button renders disabled
No $(…), backticks, <(…), brace expansion {a,b,c}, or eval/exec in any Bash tool callVibes' safe-shell filter forces manual approval on these patterns even in Bypass mode. Emit separate commands (mkdir -p a && mkdir -p b) or print each value with its own command and reason about the output — do not capture into a shell variable

Gotchas

IssueResolution
getUiComponentSchemas returns a partial-failure entryPick a different block from discoverUiComponents; do not silently continue without a schema
Body references {!$attrs.foo} but foo is not under schema.json properties.attributes.propertiesAdd foo to schema.json properties.attributes.properties OR remove the body reference
Output written outside <pkgDir>/uiWidgets/<widgetName>/<pkgDir> = <packageDirectories[].path>/main/default (see references/widget-bundle-layout.md). Dropping the main/default/ segment is the common cause of widgets landing at force-app/uiWidgets/... instead of force-app/main/default/uiWidgets/...
if bound directly to a raw string or number relies on truthiness and is unreliableBind to a lightning__booleanType property, or use a formula comparison that evaluates to boolean
tile/button renders but does nothing when clickedNo actions.click entry was set — an action-less button renders disabled by design. Add one (see Actions above)
Using action/sendMessage for pure navigation, or action/openLink when the agent should respondaction/openLink is synchronous and does not consume a turn; action/sendMessage is asynchronous and earns a fresh turn. Pick the one matching the intended UX

Reference File Index

FileWhen to read
references/widget-meta-directives.mdFor forEach / forItem (iteration) and if (conditional rendering), including nested loops
references/schema-from-lightning-type.mdWhen lightningTypeSchema is provided; how to derive the widget schema.json from an Apex-backed Lightning Type
references/widget-bundle-layout.mdFolder layout, -meta.xml shape, <pkgDir> resolution rules
references/widget-formulas.mdSupported formula functions and operators
examples/single-object.jsonSingle-object pattern (root binding via {!$attrs.X}, no iteration)
examples/list-with-foreach.jsonAny list-iteration case — root-level collections, nested lists, and lists embedded inside a single-object widget (e.g. iterating a List<InnerClass> inside an outer Apex payload)
examples/conditional.jsonConditional pattern (if on meta, including if + forEach together)
examples/formulas.jsonFormula usage — text/arithmetic/date transforms, IF/AND/NOT driving both a tile/text and meta.if

© forcedotcom, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files (references) in skills/platform-widget-generate of forcedotcom/sf-skills.

  • SKILL.md
  • examples/conditional.json
  • examples/formulas.json
  • examples/list-with-foreach.json
  • examples/single-object.json
  • references/schema-from-lightning-type.md
  • references/widget-bundle-layout.md
  • references/widget-formulas.md
  • references/widget-meta-directives.md

Open the folder on GitHubat commit 3c15867

Compare with similar skills

Platform Widget Generate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Platform Widget Generate compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Platform Widget Generate this skillforcedotcom/sf-skills1.1k—~5.8kAutomated safety check: PassApache-2.0
Hermes Agent Skill AuthoringNousResearch/hermes-agent252k—~3.6kAutomated safety check: PassMIT
Configuring Oauth2 Authorization Flowmukul975/Anthropic-Cybersecurity-Skills34k—~1.7kAutomated safety check: PassApache-2.0
Detecting Broken Object Property Level Authorizationmukul975/Anthropic-Cybersecurity-Skills34k—~4kAutomated safety check: PassApache-2.0
Makepad Widgetssickn33/agentic-awesome-skills47k2 repos~1.7kAutomated safety check: PassMIT
Implementing GCP Binary Authorizationmukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.0

Similar skills

  • Hermes Agent Skill Authoring

    NousResearch/hermes-agent

    Author in-repo SKILL.md files: frontmatter and structure. An agent skill from NousResearch/hermes-agent.

    252k GitHub stars~3.6k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Configuring Oauth2 Authorization Flow

    mukul975/Anthropic-Cybersecurity-Skills

    Configures secure OAuth 2.0 authorization flows, including Authorization Code with PKCE, Client Credentials, and Device Authorization Grant, covering flow selection, PKCE implementation, token…

    34k GitHub stars~1.7k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Detecting Broken Object Property Level Authorization

    mukul975/Anthropic-Cybersecurity-Skills

    Detect and test for OWASP API3:2023 Broken Object Property Level Authorization (BOPLA), covering excessive data exposure in API responses and mass assignment via injected request-body properties.

    34k GitHub stars~4k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Makepad Widgets

    sickn33/agentic-awesome-skills

    Version: makepad-widgets (dev branch) | Last Updated: 2026-01-19 Check for updates: https://crates.io/crates/makepad-widgets

    47k GitHub starsUsed in 2 repos~1.7k tokens
    Auto-check passed
  • Implementing GCP Binary Authorization

    mukul975/Anthropic-Cybersecurity-Skills

    Implements GCP Binary Authorization end to end, including creating KMS-backed attestors, Container Analysis notes, deploy-time policies, and signing image attestations, so that only trusted…

    34k GitHub stars~2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Contact Widget

    nexu-io/open-design

    Self-contained floating chat widget with welcome screen, social links, meeting button, and message input.

    100k GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed

More from forcedotcom/sf-skills

All 248 skills in this repo
  • Agentforce Architecture Analyze

    forcedotcom/sf-skills

    Declared architecture snapshot for one Agentforce agent: planner, topics, actions, flows, Apex, prompt templates, and NGA plugins.

    1.1k GitHub stars~3.6k tokensUpdated 5 days ago
    Auto-check passed
  • Agentforce D360 Analyze

    forcedotcom/sf-skills

    Data Cloud 360° view of a single Agentforce session. An agent skill from forcedotcom/sf-skills.

    1.1k GitHub stars~2.9k tokensUpdated 5 days ago
    Auto-check passed
  • Apply a Salesforce sandbox post-copy automation JSON config against a target org.

    1.1k GitHub stars~5.3k tokensUpdated 5 days ago
    Auto-check: notes
  • Apply a Salesforce sandbox post-copy automation JSON config against a target org.

    1.1k GitHub stars~5.4k tokensUpdated 5 days ago
    Auto-check: notes
  • Design Systems Slds Apply

    forcedotcom/sf-skills

    Apply SLDS-compliant UI using the correct blueprints, styling hooks, utility classes, and icons.

    1.1k GitHub stars~3.7k tokensUpdated 5 days ago
    Auto-check passed
  • Experience Lwc Generate

    forcedotcom/sf-skills

    Lightning Web Components with PICKLES methodology and 165-point scoring.

    1.1k GitHub stars~2.4k tokensUpdated 5 days ago
    Auto-check passed

Questions about Platform Widget Generate

What does Platform Widget Generate do?

A skill your agent uses to author a complete HXL WidgetBundle (UEM body + schema.json + -meta.xml). Platform Widget Generate is an agent skill from forcedotcom/sf-skills.xml).

When should I use Platform Widget Generate?

Platform Widget Generate fits situations like: author a complete HXL WidgetBundle (UEM body + schema.json + -meta.xml); : user asks for a widget; rich UI surface for any subject; the prompt names only an entity.

How do I install Platform Widget Generate in Claude Code?

Run `npx skills add forcedotcom/sf-skills --skill platform-widget-generate -a claude-code`. Or copy the skill folder (skills/platform-widget-generate in forcedotcom/sf-skills) into .claude/skills/platform-widget-generate in your project. Claude Code loads it when a task matches its description.

How do I install Platform Widget Generate in Codex?

Run `npx skills add forcedotcom/sf-skills --skill platform-widget-generate -a codex`. Or copy the skill folder (skills/platform-widget-generate in forcedotcom/sf-skills) into .agents/skills/platform-widget-generate in your project. Codex loads it when a task matches its description.

Can I use Platform Widget Generate in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forcedotcom/sf-skills --skill platform-widget-generate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/platform-widget-generate, .gemini/skills/platform-widget-generate, .github/skills/platform-widget-generate and .opencode/skills/platform-widget-generate in your project.

What does Platform Widget Generate need to run?

SKILL.md names no scripts, command-line tools or credentials: Platform Widget Generate is instructions for the agent only.

Does Platform Widget Generate access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Platform Widget Generate safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Platform Widget Generate use?

Platform Widget Generate is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Platform Widget Generate use?

About 5.8k tokens (SKILL.md is roughly 23k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.7k tokens, read only when the agent opens those files.

What are the alternatives to Platform Widget Generate?

Skills that share tags, products or a category with Platform Widget Generate: Hermes Agent Skill Authoring (NousResearch/hermes-agent, 252k stars), Configuring Oauth2 Authorization Flow (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Detecting Broken Object Property Level Authorization (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Makepad Widgets (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Platform Widget Generate?

forcedotcom (a GitHub organization) maintains it in forcedotcom/sf-skills, which has 1,058 GitHub stars. The repository holds 248 skills in this directory. The repository was last updated on October 3, 2026.

Source: forcedotcom/sf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.