Constraints that only bite in a real managed-package install of Portwood — global visibility, Flow Apex-Defined types, namespace-prefixed keys, USERMODE on internal reads, immutable API names.

Apache-2.0Auto-check passedDocuments & Office

Install Managed Package Rules

skills CLI
$ npx skills add Portwood-Global-Solutions/Portwood --skill managed-package-rules -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Portwood-Global-Solutions/Portwood managed-package-rules --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Portwood-Global-Solutions/Portwood.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/managed-package-rules .claude/skills/managed-package-rules && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
managed-package-rules
GitHub stars
126
Token cost
~1.2k tokens
SKILL.md length
597 words
Files
1
Skills in repo
7
Repo updated
First seen
Licence
Apache-2.0

At a glance

Constraints that only bite in a real managed-package install of Portwood — global visibility, Flow Apex-Defined types, namespace-prefixed keys, USERMODE on internal reads, immutable API names.

  • Works in 4 steps: Top-level / standalone class. Flow… → global class. → @AuraEnabled members. → …
  • Adding Apex a subscriber must see
  • SKILL.md covers Only global Apex is visible to…, Flow Apex-Defined variable…, API names are frozen forever and Namespace-prefixed keys break JS, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Managed Package Rules is an agent skill from Portwood-Global-Solutions/Portwood. Constraints that only bite in a real managed-package install of Portwood — global visibility, Flow Apex-Defined types, namespace-prefixed keys, USERMODE on internal reads, immutable API names. Use when adding Apex a subscriber must see, building a Flow action, or debugging something that works in a scratch org but fails in a package install.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Documents & Office, covering CRM management. It works with Salesforce. The repository describes itself as: Free, native document generation for Salesforce. PDF, DOCX, XLSX, PPTX — merge tags, images, barcodes, QR codes, bulk generation, Flow actions. 100% Apex + LWC, zero external… The licence is Apache-2.0.

When your agent uses it

  • Adding Apex a subscriber must see
  • Building a Flow action
  • Debugging something that works in a scratch org but fails in a package install

Example prompts

  • “Use the managed-package-rules skill to constraint that only bite in a real managed-package install of Portwood — global visibility, Flow…”
  • “/managed-package-rules”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Top-level / standalone class. Flow ignores inner and nested classes entirely.
  2. global class.
  3. @AuraEnabled members.
  4. global no-arg constructor.

What it can do on your machine

Read from SKILL.md and the folder at commit 70ede0c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Managed Package Rules loads about 1.2k tokens when it runs. Until then it costs about 92 tokens; SKILL.md has 597 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~92
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Portwood-Global-Solutions/Portwood at commit 70ede0c, republished under its Apache-2.0 licence (© Portwood-Global-Solutions). 597 words, ~1,165 tokens.

Download SKILL.mdSave it as .claude/skills/managed-package-rules/SKILL.md (or your agent's skills folder).
name
managed-package-rules
description
Constraints that only bite in a real managed-package install of Portwood — global visibility, Flow Apex-Defined types, namespace-prefixed keys, USER_MODE on internal reads, immutable API names. Use when adding Apex a subscriber must see, building a Flow action, or debugging something that works in a scratch org but fails in a package install.

Managed-package constraints

Portwood ships as Managed 2GP, namespace portwoodglobal. A large class of bugs exists only in a real subscriber install and cannot be reproduced in a no-namespace scratch org. If something works in dev and fails in an install, start here.

Only global Apex is visible to subscribers

public classes and methods are invisible in a subscriber org.

  • An @InvocableMethod must be global to appear in a subscriber's Flow Builder.
  • Helper classes a subscriber is meant to call must be global, along with their inner types, fields and methods.

Flow Apex-Defined variable types — all four are required

For a type to be selectable as a Flow Apex-Defined variable in a subscriber org:

  1. Top-level / standalone class. Flow ignores inner and nested classes entirely.
  2. global class.
  3. @AuraEnabled members.
  4. global no-arg constructor.

Missing any one produces the same symptom: the action appears, but its variable type can't be selected. This cost three separate releases to get right, each time because only one of the four was missing. Verify in a real subscriber install or a namespaced scratch org — a no-namespace staging org cannot show you the failure.

API names are frozen forever

Everything shipped is immutable: DocGen_Template__c, DocGenService, DocGen_Admin, the portwoodglobal namespace, the Canvas picklist value. Display names (labels, descriptions, user-visible strings) can change; API names cannot.

Two scheduled job names deliberately keep their old strings because they're matched by CronJobDetail.Name in orgs that already scheduled them: DocGen Signature Reminders and DocGen Chart CV Reaper.

2GP also cannot drop Apex classes without the "Remove Metadata Components" DevHub feature — the workaround is inert stubs.

Namespace-prefixed keys break JS

In a subscriber org, SObject field keys come back namespace-prefixed:

  • row.Field__c is undefined in a shipped package — it's row.portwoodglobal__Field__c. Use @salesforce/schema imports or a normalizing mapper in LWC.
  • getPopulatedFieldsAsMap() keys are prefixed too. Prefer direct field access.

Neither reproduces in a no-namespace org. A namespaced build is the real gate.

Show full SKILL.md (278 more words)Show less

WITH USER_MODE on internal reads

Portwood's internal ContentVersions (docgen_tmpl_html_*, docgen_tmpl_xml_*) have ContentDocumentLink.Visibility = InternalUsers, which is invisible under USER_MODE — the read silently returns empty and the caller falls back to something degraded. Use the FLS-guard + WITH SYSTEM_MODE hybrid for these.

The same applies to a newly packaged field: the build's test user has no permission set, so WITH USER_MODE fails the package build with "No such column" on a field that plainly exists. Use SYSTEM_MODE plus an FLS guard for internal config reads.

Guest-context rules

  • Guest profiles need the guest FLS-guard variants, not the admin ones — the per-field verdict throws for guests even when the permission set grants access.
  • @AuraEnabled(cacheable=true) serves stale empty results to guests. Never cache context-sensitive Apex.
  • Every guest-reachable SYSTEM_MODE query must be token-keyed, never keyed by a guessable Id — that shape has already produced one IDOR.
  • A guest LWC silently fails to render if the guest can't see the recordId. Check sharing before debugging the component.

No external callouts

Portwood is 100% native — no external services, APIs, or callouts, and document data never leaves the org. Client-side libraries are vendored as pinned static resources, not pulled from npm at build time. If you add or update one: keep it patched, retain its license/NOTICE, and disclose it.

Extension points exist precisely so the non-native hop can live outside the package — see DocGenAiProvider and DocGenDataProvider, both resolved by Type.forName with a namespace fallback.

Testing the things a scratch org can't show you

A namespaced pre-flight org catches build traps in minutes rather than after a 20–40 minute package build: deploy plus RunLocalTests, without assigning the permission set, so you see exactly what the build's test user sees.

© Portwood-Global-Solutions, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/managed-package-rules of Portwood-Global-Solutions/Portwood.

Open the folder on GitHubat commit 70ede0c

Compare with similar skills

Managed Package Rules next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Managed Package Rules compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Managed Package Rules this skillPortwood-Global-Solutions/Portwood126—~1.2kAutomated safety check: PassApache-2.0
Automation Sandbox Post Copy Config Generateforcedotcom/sf-skills1.1k—~4.1kAutomated safety check: PassApache-2.0
Automation Sandbox Post Copy Config Generateforcedotcom/sf-skills1.1k—~4.2kAutomated safety check: PassApache-2.0
Gh Bot Commentjetstreamapp/jetstream127—~616Automated safety check: PassCustom licence
External Consumersforcedotcom/salesforcedx-vscode1k—~1.8kAutomated safety check: PassBSD-3-Clause
Salesforce DeveloperJeffallan/claude-skills12k—~1.9kAutomated safety check: PassMIT

Similar skills

  • Generate the JSON config file that the Salesforce sandbox post-copy automation tool consumes, from a customer SOP in any format (PDF, xlsx, csv, JSON, docx, Markdown, plain text, or a screenshot of…

    1.1k GitHub stars~4.1k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Generate the JSON config file that the Salesforce sandbox post-copy automation tool consumes, from a customer SOP in any format (PDF, xlsx, csv, JSON, docx, Markdown, plain text, or a screenshot of…

    1.1k GitHub stars~4.2k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Gh Bot Comment

    jetstreamapp/jetstream

    Post GitHub PR/issue comments, reviews, and review replies as the Jetstream bot account instead of the user's personal account.

    127 GitHub stars~616 tokensUpdated today
    DevelopmentAuto-check passed
  • External Consumers

    forcedotcom/salesforcedx-vscode

    Known external consumers of APIs from this monorepo's extensions.

    1k GitHub stars~1.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Salesforce Developer

    Jeffallan/claude-skills

    Writes Apex, Lightning Web Components and SOQL for the Salesforce platform, with bulkified triggers, governor-limit checks, 90% test coverage and Salesforce DX deployment.

    12k GitHub stars~1.9k tokensUpdated 7 days ago
    DevelopmentAuto-check passed
  • Implementing Zero Trust For SaaS Applications

    mukul975/Anthropic-Cybersecurity-Skills

    Secures SaaS apps (Microsoft 365, Google Workspace, Salesforce, Slack) via CASB/SSPM deployment, conditional access policies, OAuth app governance, and session-level DLP controls enforcing identity…

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed

More from Portwood-Global-Solutions/Portwood

  • Canvas Designer

    Portwood-Global-Solutions/Portwood

    Work on Portwood's Canvas designer (docGenCanvas LWC and canvasModel.js).

    126 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Dev Setup

    Portwood-Global-Solutions/Portwood

    Get from a fresh clone of Portwood to a working, fully-tested Salesforce org.

    126 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • HTML Template Authoring

    Portwood-Global-Solutions/Portwood

    Author or repair a Portwood HTML template that renders correctly through Blob.toPdf (Flying Saucer).

    126 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Triage Report

    Portwood-Global-Solutions/Portwood

    Decide whether a Portwood bug report is a real code defect or a template-authoring problem, before any code is written.

    126 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Fix Merge Tag

    Portwood-Global-Solutions/Portwood

    Fix a Portwood merge-tag or parser bug correctly across all of its resolution paths.

    126 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Run Tests

    Portwood-Global-Solutions/Portwood

    Run Portwood's test suites — the one-command QA harness, the anonymous-Apex e2e scripts, Apex unit tests, prettier, and Code Analyzer.

    126 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Managed Package Rules

What does Managed Package Rules do?

Constraints that only bite in a real managed-package install of Portwood — global visibility, Flow Apex-Defined types, namespace-prefixed keys, USERMODE on internal reads, immutable API names. Managed Package Rules is an agent skill from Portwood-Global-Solutions/Portwood. Constraints that only bite in a real managed-package install of Portwood — global visibility, Flow Apex-Defined types, namespace-prefixed keys, USERMODE on internal reads, immutable API names.

When should I use Managed Package Rules?

Managed Package Rules fits situations like: adding Apex a subscriber must see; building a Flow action; debugging something that works in a scratch org but fails in a package install.

How do I install Managed Package Rules in Claude Code?

Run `npx skills add Portwood-Global-Solutions/Portwood --skill managed-package-rules -a claude-code`. Or copy the skill folder (.claude/skills/managed-package-rules in Portwood-Global-Solutions/Portwood) into .claude/skills/managed-package-rules in your project. Claude Code loads it when a task matches its description.

How do I install Managed Package Rules in Codex?

Run `npx skills add Portwood-Global-Solutions/Portwood --skill managed-package-rules -a codex`. Or copy the skill folder (.claude/skills/managed-package-rules in Portwood-Global-Solutions/Portwood) into .agents/skills/managed-package-rules in your project. Codex loads it when a task matches its description.

Can I use Managed Package Rules in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Portwood-Global-Solutions/Portwood --skill managed-package-rules -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/managed-package-rules, .gemini/skills/managed-package-rules, .github/skills/managed-package-rules and .opencode/skills/managed-package-rules in your project.

What does Managed Package Rules need to run?

SKILL.md names no scripts, command-line tools or credentials: Managed Package Rules is instructions for the agent only.

Does Managed Package Rules access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Managed Package Rules safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Managed Package Rules use?

Managed Package Rules is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Managed Package Rules use?

About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Managed Package Rules?

Skills that share tags, products or a category with Managed Package Rules: Automation Sandbox Post Copy Config Generate (forcedotcom/sf-skills, 1.1k stars), Automation Sandbox Post Copy Config Generate (forcedotcom/sf-skills, 1.1k stars), Gh Bot Comment (jetstreamapp/jetstream, 127 stars) and External Consumers (forcedotcom/salesforcedx-vscode, 1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Managed Package Rules?

Portwood-Global-Solutions (a GitHub organization) maintains it in Portwood-Global-Solutions/Portwood, which has 126 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 9, 2026.

Source: Portwood-Global-Solutions/Portwood on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.