Services Extension Consumption
forcedotcom/salesforcedx-vscode
Consume the salesforcedx-vscode-services extension API. An agent skill from forcedotcom/salesforcedx-vscode.
Create reusable agent users for Omni-Channel setup and routing validation.
$ npx skills add forcedotcom/sf-skills --skill service-omni-agent-users-create -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install forcedotcom/sf-skills service-omni-agent-users-create --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/service-omni-agent-users-create .claude/skills/service-omni-agent-users-create && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "service-omni-agent-users-create" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/service-omni-agent-users-create into .claude/skills/service-omni-agent-users-create/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "service-omni-agent-users-create", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/forcedotcom/sf-skills/tree/main/skills/service-omni-agent-users-createType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add forcedotcom/sf-skills --skill service-omni-agent-users-create -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install forcedotcom/sf-skills service-omni-agent-users-create --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/service-omni-agent-users-create .agents/skills/service-omni-agent-users-create && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "service-omni-agent-users-create" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/service-omni-agent-users-create into .agents/skills/service-omni-agent-users-create/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "service-omni-agent-users-create", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forcedotcom/sf-skills --skill service-omni-agent-users-create -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install forcedotcom/sf-skills service-omni-agent-users-create --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/service-omni-agent-users-create .cursor/skills/service-omni-agent-users-create && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "service-omni-agent-users-create" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/service-omni-agent-users-create into .cursor/skills/service-omni-agent-users-create/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "service-omni-agent-users-create", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/forcedotcom/sf-skills.git --path skills/service-omni-agent-users-create--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add forcedotcom/sf-skills --skill service-omni-agent-users-create -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install forcedotcom/sf-skills service-omni-agent-users-create --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/service-omni-agent-users-create .gemini/skills/service-omni-agent-users-create && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "service-omni-agent-users-create" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/service-omni-agent-users-create into .gemini/skills/service-omni-agent-users-create/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "service-omni-agent-users-create", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install forcedotcom/sf-skills service-omni-agent-users-createInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add forcedotcom/sf-skills --skill service-omni-agent-users-create -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/service-omni-agent-users-create .github/skills/service-omni-agent-users-create && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "service-omni-agent-users-create" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/service-omni-agent-users-create into .github/skills/service-omni-agent-users-create/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "service-omni-agent-users-create", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forcedotcom/sf-skills --skill service-omni-agent-users-create -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install forcedotcom/sf-skills service-omni-agent-users-create --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/service-omni-agent-users-create .opencode/skills/service-omni-agent-users-create && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "service-omni-agent-users-create" agent skill from https://github.com/forcedotcom/sf-skills/tree/main/skills/service-omni-agent-users-create into .opencode/skills/service-omni-agent-users-create/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "service-omni-agent-users-create", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
service-omni-agent-users-createCreate reusable agent users for Omni-Channel setup and routing validation.
Service Omni Agent Users Create is an agent skill from forcedotcom/sf-skills. Create reusable agent users for Omni-Channel setup and routing validation. TRIGGER when users ask to create Omni agents, provision Omni test users, seed sandbox users for routing, create Omni-Channel routing agents, or repair missing demo agents. DO NOT TRIGGER for queue membership, permission-set assignment, or supervisor-user creation.
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 11 other files, including scripts, reference files and assets (for example `references/apex-patterns.md`, `references/apex-template-notes.md` and `scripts/detect-and-create.sh`).
It sits in Sales & Support. It works with Salesforce. The repository describes itself as: Salesforce's curated collection of agent skills for building applications. Optimized for Agentforce Vibes, compatible with all AI tools. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit 4bbae5c. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
BashReadWriteEditGlobGrepFrom allowed-tools in the SKILL.md frontmatter.
Ships 4 files in scripts/ (Shell and Python), which the agent can run.
Shell commands in SKILL.md call:
bashsfFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Service Omni Agent Users Create loads about 2.2k tokens when it runs, and up to ~4.9k if it reads all its reference files. Until then it costs about 93 tokens; SKILL.md has 946 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Bash, Read, Write, Edit, Glob, GrepAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from forcedotcom/sf-skills at commit 4bbae5c, republished under its Apache-2.0 licence (© forcedotcom). 946 words, ~2,205 tokens.
.claude/skills/service-omni-agent-users-create/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.Create N agent users on a Salesforce org via Anonymous Apex so Omni-Channel has agents to route work to. Usernames follow a deterministic per-org pattern, detection is SOQL-based, and the skill inserts only the users that are missing — so it is safe to re-run. It is invoked by service-omni-channel-setup-coordinate after service-omni-base-settings-configure enables Omni-Channel; assigning permission sets (service-omni-permission-set-assign) and adding users to queues (service-omni-queue-members-assign) are separate leaves. Supervisor users come from service-omni-supervisor-users-create.
Confirm once, up front:
org-alias (required, no default) — must resolve via sf org display.3, range 1..10).Standard User for portability). The coordinator overrides this to a Service Cloud profile so agents consume Service Cloud licenses; on many CDOs the Salesforce license pool is saturated while Service Cloud has free slots.Usernames and passwords are never accepted from the operator — both are generated (usernames from the org suffix, passwords via Anonymous Apex). Operator-supplied credentials would break re-run detection and risk weak or leaked secrets.
sf CLI (My Domain URL, not .lightning.force.com), Service Cloud license present, sf CLI ≥ 2.139.6.PermissionsModifyAllData and PermissionsManagePasswordPolicies (standard on System Administrator).safe_to_write as IsSandbox OR TrialExpirationDate != null OR OrganizationType in {Developer Edition, Base Edition}, and the skill blocks with no override when it is false. CDOs, scratch orgs, and dev orgs are permitted.Password handling (fail-closed). Passwords are set by Anonymous Apex System.setPassword (sf user password generate cannot target Apex-inserted users — it fails with NamedOrgNotFoundError). The password literal appears in the inline executeAnonymous debug log and, only when a debug-log TraceFlag is active for the running user, in a queryable ApexLog. The wrapper therefore fails closed before the first System.setPassword: it proves via a SOQL-filtered Tooling API query (ExpirationDate > now) that no active TraceFlag exists. If safety cannot be positively proven — the running user is unresolved, the query fails or is unparseable, or any active TraceFlag exists — it generates no password at all; the user is left ACTIVE, flagged password_status:"reset_required", and a security_warning explains why. It never deletes logs, so no plaintext can reach an ApexLog and unrelated audit logs are untouched. If System.setPassword itself fails for a user, that user is kept ACTIVE and flagged for reset.
# read-only preview (never writes)
bash scripts/detect-and-create.sh plan <org-alias> [count] [profile-name]
# detect, enforce safe_to_write, then insert only the missing users
bash scripts/detect-and-create.sh run <org-alias> [count=3] [profile-name="Standard User"]detect-and-create.sh is the canonical entry point: it re-runs detection, enforces the production guard, and only then inserts. Do not call scripts/run-create.sh directly — it is internal and does not enforce the guard on its own.
Detection. The detector derives an 8-char suffix from Organization.Id (substring(10,18), lowercased), resolves the profile by name, and queries User for agent{i}.<suffix>@example.com to find which of the count slot indexes are occupied. A stable, deterministic pattern is what makes re-runs idempotent — the suffix is never a timestamp or UUID.
Insertion. The Apex loads assets/create-users.apex.template, substitutes __COUNT__/__PROFILE_ID__/__SUFFIX__, and inserts only the missing indexes. It re-checks existing users inside the transaction, which prevents a single run from double-inserting; across concurrent runs the in-transaction check is not a guarantee (both can pass their pre-query before either commits), so duplicate protection there relies on the global username-uniqueness constraint plus the DUPLICATE_USERNAME retry (see references/apex-template-notes.md). It enables the Service Cloud feature (UserPermissionsSupportUser=true) so users can go online in Omni; if the profile's license does not allow it, the Apex strips the flag and retries (users are still created, but need a Service-Cloud-license profile for full Omni). Each created user is reported via AGENT_USER_CREATED|<id>|<username>|<email> (no password in the marker — passwords are set by the separate System.setPassword submission).
Verification. After insertion the detector re-runs and must show missing_count == 0; otherwise the skill fails (the Apex reported success but the users did not persist).
detect-and-create.sh emits a single JSON object with status ∈ created | partial | reused | action_needed | blocked, plus detect (mirrors the detector), create (mirrors the inserter, null when nothing was created), top-level reused_users, created_count, reused_count, total_present_after, users_needing_password_reset, action_required, and safe_to_write. The coordinator combines reused_users with newly created users so mixed runs configure presence and skills for the complete requested agent set.
created — every missing index landed with a working password.partial — some landed but not all, or any user needs a manual password reset, or inactive occupants were found.reused — all requested users already existed; nothing created.action_needed — plan mode only; reports missing indexes without writing.blocked — precondition failed (safe_to_write=false, unresolved profile/suffix, or nothing inserted).create.created_users[].password is populated only for users created this run whose System.setPassword succeeded; password_status:"reset_required" means the user is ACTIVE but has no working password yet. Exit code is 0 for created/partial/action_needed/reused, 1 for blocked.
Generated passwords are a secret: the returned JSON is the only place they appear. Any caller that persists stdout must write it only to a restricted CREDENTIALS.json (mode 0600), redact it from every other artifact, and delete it after distribution — the coordinator does this automatically; standalone callers own it. Reused users' passwords are not retrievable; recover via Setup → Users → Reset Password.
DUPLICATE_USERNAME, INVALID_EMAIL, LICENSE_LIMIT_EXCEEDED) are translated into operator-friendly messages rather than surfaced raw.| File | When to read |
|---|---|
references/apex-patterns.md | Before running the Apex — Apex structure, User field defaults, password policy, and the profile-localization risk |
references/apex-template-notes.md | When user creation returns a duplicate, license, or password error — explains template substitutions and retry behavior |
assets/create-users.apex.template | Loaded by scripts/run-create.sh when missing agent users must be inserted |
scripts/detect-existing.sh | Loaded by the canonical entry point for the read-only org, profile, safety, and existing-user checks |
scripts/tests/test_user_create_security.py | Run after changing the user-creation scripts to verify production refusal and password-handling contracts |
© forcedotcom, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 7 other files (scripts, references, assets) in skills/service-omni-agent-users-create of forcedotcom/sf-skills.
Open the folder on GitHubat commit 4bbae5c
Service Omni Agent Users Create next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Service Omni Agent Users Create this skillforcedotcom/sf-skills | 1.1k | — | ~2.2k | Automated safety check: Notes | Apache-2.0 | |
| Services Extension Consumptionforcedotcom/salesforcedx-vscode | 1k | — | ~5k | Automated safety check: Pass | BSD-3-Clause | |
| Soql Lib Query Builderbeyond-the-cloud-dev/soql-lib | 154 | — | ~4.3k | Automated safety check: Pass | MIT | |
| Sf DatacloudJaganpro/sf-skills | 424 | — | ~2.7k | Automated safety check: Pass | MIT | |
| Soql Lib Selectorbeyond-the-cloud-dev/soql-lib | 154 | — | ~2k | Automated safety check: Pass | MIT | |
| Core Extension APIforcedotcom/salesforcedx-vscode | 1k | — | ~842 | Automated safety check: Pass | BSD-3-Clause |
forcedotcom/salesforcedx-vscode
Consume the salesforcedx-vscode-services extension API. An agent skill from forcedotcom/salesforcedx-vscode.
beyond-the-cloud-dev/soql-lib
Builds Salesforce SOQL queries using the SOQL Lib fluent builder API (SOQL.cls).
Jaganpro/sf-skills
Salesforce Data Cloud product orchestrator for connect→prepare→harmonize→segment→act workflows.
beyond-the-cloud-dev/soql-lib
Creates Salesforce Apex selector classes using the SOQL Lib selector pattern.
forcedotcom/salesforcedx-vscode
Public API exported by salesforcedx-vscode-core activate(). An agent skill from forcedotcom/salesforcedx-vscode.
Portwood-Global-Solutions/Portwood
Get from a fresh clone of Portwood to a working, fully-tested Salesforce org.
forcedotcom/sf-skills
Declared architecture snapshot for one Agentforce agent: planner, topics, actions, flows, Apex, prompt templates, and NGA plugins.
forcedotcom/sf-skills
Data Cloud 360° view of a single Agentforce session. An agent skill from forcedotcom/sf-skills.
forcedotcom/sf-skills
Apply a Salesforce sandbox post-copy automation JSON config against a target org.
forcedotcom/sf-skills
Apply a Salesforce sandbox post-copy automation JSON config against a target org.
forcedotcom/sf-skills
Apply SLDS-compliant UI using the correct blueprints, styling hooks, utility classes, and icons.
forcedotcom/sf-skills
Lightning Web Components with PICKLES methodology and 165-point scoring.
Works with
Categories
Create reusable agent users for Omni-Channel setup and routing validation. Service Omni Agent Users Create is an agent skill from forcedotcom/sf-skills. Create reusable agent users for Omni-Channel setup and routing validation.
Service Omni Agent Users Create fits situations like: users ask to create Omni agents; provision Omni test users; seed sandbox users for routing; create Omni-Channel routing agents.
Run `npx skills add forcedotcom/sf-skills --skill service-omni-agent-users-create -a claude-code`. Or copy the skill folder (skills/service-omni-agent-users-create in forcedotcom/sf-skills) into .claude/skills/service-omni-agent-users-create in your project. Claude Code loads it when a task matches its description.
Run `npx skills add forcedotcom/sf-skills --skill service-omni-agent-users-create -a codex`. Or copy the skill folder (skills/service-omni-agent-users-create in forcedotcom/sf-skills) into .agents/skills/service-omni-agent-users-create in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forcedotcom/sf-skills --skill service-omni-agent-users-create -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/service-omni-agent-users-create, .gemini/skills/service-omni-agent-users-create, .github/skills/service-omni-agent-users-create and .opencode/skills/service-omni-agent-users-create in your project.
Going by SKILL.md and its folder, Service Omni Agent Users Create needs a shell and Python for the scripts in its folder and the command-line tools its instructions call (bash and sf). Our summary lists: Python 3; A Bash shell. Its frontmatter pre-approves these tools: Bash, Read, Write, Edit, Glob, Grep.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Service Omni Agent Users Create is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.7k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Service Omni Agent Users Create: Services Extension Consumption (forcedotcom/salesforcedx-vscode, 1k stars), Soql Lib Query Builder (beyond-the-cloud-dev/soql-lib, 154 stars), Sf Datacloud (Jaganpro/sf-skills, 424 stars) and Soql Lib Selector (beyond-the-cloud-dev/soql-lib, 154 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
forcedotcom (a GitHub organization) maintains it in forcedotcom/sf-skills, which has 1,067 GitHub stars. The repository holds 252 skills in this directory. The repository was last updated on October 9, 2026.
Source: forcedotcom/sf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.