Salesforce security — SfSkills domain router
Platform security and compliance: org hardening, encryption, session policy, MFA, monitoring, incident response, and TROUBLESHOOTING a specific record-access denial. Designing the sharing model itself (OWD, role hierarchy, sharing rules) is salesforce-admin.
49 skill packages live under
${CLAUDE_PLUGIN_ROOT}/skills/security/<slug>/SKILL.md. They are not
loaded — reach them by path, on demand.
Generated by scripts/build_plugin.py. Do not hand-edit.
How to find the right skill
Three mechanisms, listed in order of reliability on a fresh install. Use the first one that is available; do not stop at a guess.
1. The shipped roster (always works, no setup).
Read references/skill-index.md next to this file. It lists every
security skill package with a one-line gloss, generated from
registry/skills.json. Scan it and pick by name.
2. The MCP server (fast, needs the sfskills-mcp server connected).
Call the search_skill tool with the user's phrasing and domain: "security". It returns
ranked skill ids. get_skill then returns the package contents.
3. The search CLI (fast, needs a locally built index).
python3 "${CLAUDE_PLUGIN_ROOT}/scripts/search_knowledge.py" "<the user's question>" --domain security --json
This needs vector_index/, which is not shipped — it is gitignored
and must be built once per clone:
cd "${CLAUDE_PLUGIN_ROOT}" && python3 -m pip install -r requirements.txt && python3 scripts/build_index.py
If the command errors or reports Coverage: NONE, fall back to
mechanism 1 rather than telling the user the topic is uncovered.
Then read the package. Open the exact
${CLAUDE_PLUGIN_ROOT}/skills/<domain>/<slug>/SKILL.md the lookup
returned, plus its references/gotchas.md and
references/llm-anti-patterns.md. Do not answer from this router:
it is a map, not the territory.
Featured entry points
Curated starting points when the request is broad or the lookup is
ambiguous. This is a shortlist, not the catalogue — the roster at
references/skill-index.md has all 49.
${CLAUDE_PLUGIN_ROOT}/skills/security/org-hardening-and-baseline-config/SKILL.md— the baseline every org should already meet${CLAUDE_PLUGIN_ROOT}/skills/security/permission-set-groups-and-muting/SKILL.md— composing access with groups, and muting the over-grant${CLAUDE_PLUGIN_ROOT}/skills/security/record-access-troubleshooting/SKILL.md— why this user can (or cannot) see this record${CLAUDE_PLUGIN_ROOT}/skills/security/platform-encryption/SKILL.md— Shield Platform Encryption and everything it breaks${CLAUDE_PLUGIN_ROOT}/skills/security/mfa-enforcement-patterns/SKILL.md— MFA rollout without locking out integration users${CLAUDE_PLUGIN_ROOT}/skills/security/xss-and-injection-prevention/SKILL.md— output encoding, SOQL injection, and unsafe HTML in components${CLAUDE_PLUGIN_ROOT}/skills/security/secure-coding-review-checklist/SKILL.md— the review gate for Apex, LWC and callouts${CLAUDE_PLUGIN_ROOT}/skills/security/event-monitoring/SKILL.md— Event Monitoring, Shield log retention, and detecting misuse
Decision trees
Read the tree before activating a skill when the request could be solved more than one way, and cite the branch that decided it.
${CLAUDE_PLUGIN_ROOT}/standards/decision-trees/sharing-selection.md— OWD vs role hierarchy vs sharing rules vs manual vs Apex managed sharing
Rules
- Answer from the opened
securitypackage, never from this router. - Cite the skill id and, where one applied, the decision-tree branch.
- Never claim a topic is uncovered without pasting lookup output.
- Never deploy to an org.