Sf Org Security Audit

Standing security audit of a Salesforce org and its source - who holds ModifyAllData, ViewAllData, AuthorApex and ViewEncryptedData, the object and field matrix behind every permission set, profile sprawl, Apex class and @AuraEnabled exposure, org-wide defaults and without-sharing code, guest user and Experience Cloud surface, Named and External Credentials, secrets in source and in git history, and the Setup-only checks (Health Check, session and password policy, login IP ranges, MFA, Setup Audit Trail) that no CLI command covers. Produces a severity-ranked findings report with evidence and a fix per item. Use when onboarding an org, preparing a security review or audit response, or periodically. Not for reviewing a diff - that is the sf-security-reviewer agent - and not for writing secure Apex, which is skill sf-security-model.

grzmol Updated

File contents

grzmol/vibe-force/tree/main/skills/sf-org-security-audit commit caac0b910b

Frequently asked questions

npx skillmds@latest add grzmol/sf-org-security-audit