Agent skill

Sf Permissions

by Jaganpro in Jaganpro/sf-skills

Permission Set analysis, hierarchy viewer, and access auditing.

MITAuto-check passed

Install Sf Permissions

skills CLI
$ npx skills add Jaganpro/sf-skills --skill sf-permissions -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Jaganpro/sf-skills sf-permissions --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Jaganpro/sf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sf-permissions .claude/skills/sf-permissions && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sf-permissions
GitHub stars
424
Token cost
~1.4k tokens
SKILL.md length
506 words
Files
24 (incl. scripts, references)
Skills in repo
36
Repo updated
First seen
Licence
MIT

At a glance

Permission Set analysis, hierarchy viewer, and access auditing.

  • Works in 5 steps: Classify the request → Connect to the correct org → Use the narrowest useful query → …
  • : user asks who has access to X?
  • SKILL.md covers When This Skill Owns the Task, Required Context to Gather First, Recommended Workflow and High-Signal Rules, plus 4 more sections
  • Runs Python scripts from its folder

What it does

Sf Permissions is an agent skill from Jaganpro/sf-skills. Permission Set analysis, hierarchy viewer, and access auditing. TRIGGER when: user asks "who has access to X?", analyzes permission sets/groups, or touches .permissionset-meta.xml / .permissionsetgroup-meta.xml files. DO NOT TRIGGER when: creating new metadata (use sf-metadata), deploying permission sets (use sf-deploy), or Apex sharing logic (use sf-apex).

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 25 other files, including scripts and reference files (for example `CREDITS.md`, `README.md` and `references/agent-access-guide.md`).

The repository describes itself as: [ARCHIVED — migrated to forcedotcom/afv-library] Salesforce Skills for Agentic Coding Tools — Apex, Flow, LWC, SOQL, Agentforce, Data Cloud, OmniStudio. Read-only archive; active… The licence is MIT.

When your agent uses it

  • : user asks who has access to X?
  • Analyzes permission sets/groups
  • Touches .permissionset-meta.xml / .permissionsetgroup-meta.xml files
  • : creating new metadata (use sf-metadata)

Example prompts

  • “who has access to X?”
  • “/sf-permissions”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Classify the request
  2. Connect to the correct org
  3. Use the narrowest useful query
  4. Render findings clearly
  5. Hand off creation or deployment work

What it can do on your machine

Read from SKILL.md and the folder at commit 53c9956. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 8 files in scripts/ (Python, from the files we listed), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sf Permissions loads about 1.4k tokens when it runs, and up to ~7.5k if it reads all its reference files. Until then it costs about 94 tokens; SKILL.md has 506 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~94
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from Jaganpro/sf-skills at commit 53c9956, republished under its MIT licence (© Jaganpro). 506 words, ~1,361 tokens.

Download SKILL.mdSave it as .claude/skills/sf-permissions/SKILL.md (or your agent's skills folder). This skill also uses 23 other files; get the full folder from GitHub.
name
sf-permissions
description
Permission Set analysis, hierarchy viewer, and access auditing. TRIGGER when: user asks "who has access to X?", analyzes permission sets/groups, or touches .permissionset-meta.xml / .permissionsetgroup-meta.xml files. DO NOT TRIGGER when: creating new metadata (use sf-metadata), deploying permission sets (use sf-deploy), or Apex sharing logic (use sf-apex).
license
MIT
metadata.version
1.1.0
metadata.author
Jag Valaiyapathy
metadata.inspiration
PSLab by Oumaima Arbani (github.com/OumArbani/PSLab)

sf-permissions

Use this skill when the user needs permission analysis and access auditing: Permission Set / Permission Set Group hierarchy views, “who has access to X?” investigations, user-permission analysis, or permission-set metadata review.

When This Skill Owns the Task

Use sf-permissions when the work involves:

  • permission set / permission set group analysis
  • user access investigation
  • finding which permission grants object / field / Apex / flow / tab / custom-permission access
  • auditing or exporting permission configuration
  • reviewing permission metadata impacts

Delegate elsewhere when the user is:

  • creating new metadata definitions → sf-metadata
  • deploying permission sets → sf-deploy
  • analyzing Apex-managed sharing logic → sf-apex

Required Context to Gather First

Ask for or infer:

  • target org alias
  • whether the question is about an object, field, Apex class, flow, tab, custom permission, or specific user
  • whether the goal is hierarchy visualization, access detection, export, or metadata generation
  • whether the output should be terminal-focused or documentation-friendly

1. Classify the request
Request shapeDefault capability
“who has access to X?”permission detector
“what does this user have?”user analyzer
“show me the hierarchy”hierarchy viewer
“export this permset”exporter
“generate metadata from analysis”generator or handoff
2. Connect to the correct org

Verify sf auth before running permission analysis.

3. Use the narrowest useful query

Prefer focused analysis over broad org-wide scans unless the user explicitly wants a full audit.

When choosing identifiers, prefer stable metadata names first:

  • PermissionSet.Name
  • PermissionSetGroup.DeveloperName
  • CustomPermission.DeveloperName
  • object and field API names such as Account or Account.AnnualRevenue
  • Assignee.Username / email for user-centric checks

Use Salesforce record IDs only when:

  • the underlying object model requires ParentId or SetupEntityId, or
  • you are drilling into records returned by a prior read-only query in the same investigation
4. Render findings clearly

Use:

  • ASCII tree or table output for terminal work
  • Mermaid only when documentation benefit is clear
  • concise summaries of which permission source grants access
Show full SKILL.md (205 more words)Show less
5. Hand off creation or deployment work

Use:


High-Signal Rules

  • distinguish direct Permission Set grants from grants via Permission Set Groups
  • prefer Name / DeveloperName / API names over org-specific record IDs for first-pass investigation queries
  • be explicit about whether access is object-level, field-level, class-level, flow-level, or custom-permission-based
  • use Tooling API where required for setup entities and advanced visibility questions
  • for agent access questions, verify exact agent-name matching in permission metadata
  • when a follow-up child query requires ParentId or SetupEntityId, resolve the ID from a prior result instead of starting with copied IDs

Output Format

When finishing, report in this order:

  1. What was analyzed
  2. Org / subject scope
  3. Which permissions grant access
  4. Whether access is direct or inherited
  5. Recommended follow-up

Suggested shape:

text
Permission analysis: <hierarchy / detect / user / export>
Scope: <org, user, permission target>
Findings: <permsets / groups / access level>
Source: <direct assignment or via group>
Next step: <export, generate metadata, or deploy changes>

Cross-Skill Integration

NeedDelegate toReason
generate or modify permission metadatasf-metadatametadata authoring
deploy permission changessf-deployrollout
identify Apex classes needing grantssf-apeximplementation context
bulk user assignment analysissf-datalarger data operations

Reference Map

Start here
Specialized analysis

Score Guide

ScoreMeaning
90+strong permission analysis with clear access sourcing
75–89useful audit with minor gaps
60–74partial visibility only
< 60insufficient evidence; expand analysis

© Jaganpro, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 23 other files (scripts, references) in skills/sf-permissions of Jaganpro/sf-skills.

  • SKILL.md
  • .gitignore
  • CREDITS.md
  • LICENSE
  • README.md
  • references/agent-access-guide.md
  • references/permission-model.md
  • references/soql-reference.md
  • references/usage-examples.md
  • references/workflow-examples.md
  • requirements.txt
  • scripts/__init__.py
  • scripts/auth.py
  • scripts/cli.py
  • scripts/hierarchy_viewer.py
  • scripts/metadata_fetcher.py
  • scripts/permission_detector.py
  • scripts/permission_exporter.py
  • scripts/renderers
  • … and 5 more

Open the folder on GitHubat commit 53c9956

Compare with similar skills

Sf Permissions next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sf Permissions compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sf Permissions this skillJaganpro/sf-skills424—~1.4kAutomated safety check: PassMIT
Auditing GCP Iam Permissionsmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.0
Production Auditaffaan-m/ECC276k1 repos~1.9kAutomated safety check: PassMIT
Aims Auditalirezarezvani/claude-skills28k—~1.3kAutomated safety check: PassMIT
Geo Auditsickn33/agentic-awesome-skills47k1 repos~3.4kAutomated safety check: NotesMIT
OmniRoute Audit and Policy CLIdiegosouzapw/OmniRoute75k—~733Automated safety check: PassMIT

Similar skills

  • Auditing GCP Iam Permissions

    mukul975/Anthropic-Cybersecurity-Skills

    Auditing Google Cloud Platform IAM permissions to identify overly permissive bindings, primitive role usage, service account key proliferation, and cross-project access risks using gcloud CLI…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Production Audit

    affaan-m/ECC

    Local-evidence production readiness audit for shipped apps, pre-launch reviews, post-merge checks, and "what breaks in prod?" questions without sending repo data to an external audit service.

    276k GitHub starsUsed in 1 repo~1.9k tokens
    Product & Project ManagementAuto-check passed
  • Aims Audit

    alirezarezvani/claude-skills

    /cs:aims-audit <scope — ISO/IEC 42001 AIMS internal-audit 6-question forcing interrogation.

    28k GitHub stars~1.3k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Geo Audit

    sickn33/agentic-awesome-skills

    Full website GEO+SEO audit with parallel subagent delegation.

    47k GitHub starsUsed in 1 repo~3.4k tokens
    Marketing & SEOAuto-check: notes
  • OmniRoute Audit and Policy CLI

    diegosouzapw/OmniRoute

    Command reference for omniroute's audit, logs, policy and telemetry commands: search and export audit trails, manage access policies and review request history for compliance work.

    75k GitHub stars~733 tokensUpdated today
    SecurityAuto-check passed
  • Audit Preparation

    sickn33/agentic-awesome-skills

    Audit preparation register: required document, period covered, request and receipt dates, preparer and reviewer, auditor queries and adjustments.

    47k GitHub starsUsed in 1 repo~5.3k tokens
    Legal & ComplianceAuto-check passed

More from Jaganpro/sf-skills

All 36 skills in this repo
  • Agentforce session tracing extraction and analysis. An agent skill from Jaganpro/sf-skills.

    424 GitHub stars~1.8k tokensUpdated 5 mo ago
    Auto-check passed
  • Sf AI Agentscript

    Jaganpro/sf-skills

    Agent Script DSL for deterministic Agentforce agents. An agent skill from Jaganpro/sf-skills.

    424 GitHub stars~3.8k tokensUpdated 5 mo ago
    Auto-check passed
  • Sf Datacloud

    Jaganpro/sf-skills

    Salesforce Data Cloud product orchestrator for connect→prepare→harmonize→segment→act workflows.

    424 GitHub stars~2.7k tokensUpdated 5 mo ago
    Auto-check passed
  • Sf Diagram Mermaid

    Jaganpro/sf-skills

    Salesforce architecture diagrams using Mermaid with ASCII fallback.

    424 GitHub stars~1.4k tokensUpdated 5 mo ago
    Auto-check passed
  • Sf Diagram Nanobananapro

    Jaganpro/sf-skills

    AI-powered image generation for Salesforce visuals via Nano Banana Pro.

    424 GitHub stars~1.6k tokensUpdated 5 mo ago
    Auto-check passed
  • Sf Flow

    Jaganpro/sf-skills

    Creates and validates Salesforce Flows with 110-point scoring.

    424 GitHub stars~1.8k tokensUpdated 5 mo ago
    Auto-check passed

Questions about Sf Permissions

What does Sf Permissions do?

Permission Set analysis, hierarchy viewer, and access auditing. Sf Permissions is an agent skill from Jaganpro/sf-skills. Permission Set analysis, hierarchy viewer, and access auditing.

When should I use Sf Permissions?

Sf Permissions fits situations like: : user asks who has access to X?; analyzes permission sets/groups; touches .permissionset-meta.xml / .permissionsetgroup-meta.xml files; : creating new metadata (use sf-metadata).

How do I install Sf Permissions in Claude Code?

Run `npx skills add Jaganpro/sf-skills --skill sf-permissions -a claude-code`. Or copy the skill folder (skills/sf-permissions in Jaganpro/sf-skills) into .claude/skills/sf-permissions in your project. Claude Code loads it when a task matches its description.

How do I install Sf Permissions in Codex?

Run `npx skills add Jaganpro/sf-skills --skill sf-permissions -a codex`. Or copy the skill folder (skills/sf-permissions in Jaganpro/sf-skills) into .agents/skills/sf-permissions in your project. Codex loads it when a task matches its description.

Can I use Sf Permissions in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Jaganpro/sf-skills --skill sf-permissions -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sf-permissions, .gemini/skills/sf-permissions, .github/skills/sf-permissions and .opencode/skills/sf-permissions in your project.

What does Sf Permissions need to run?

Going by SKILL.md and its folder, Sf Permissions needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Sf Permissions access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Sf Permissions safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Sf Permissions use?

Sf Permissions is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sf Permissions use?

About 1.4k tokens (SKILL.md is roughly 5.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.1k tokens, read only when the agent opens those files.

What are the alternatives to Sf Permissions?

Skills that share tags, products or a category with Sf Permissions: Auditing GCP Iam Permissions (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Production Audit (affaan-m/ECC, 276k stars), Aims Audit (alirezarezvani/claude-skills, 28k stars) and Geo Audit (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sf Permissions?

Jaganpro (a GitHub user) maintains it in Jaganpro/sf-skills, which has 424 GitHub stars. The repository holds 36 skills in this directory. The repository was last updated on April 27, 2026.

Source: Jaganpro/sf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.