# Salesforce Security

> Router for the 49 SfSkills `security` skill packages. Platform security and compliance: org hardening, encryption, session policy, MFA, monitoring, incident response, and TROUBLESHOOTING a specific record-access denial. Designing the sharing model itself (OWD, role hierarchy, sharing rules) is salesforce-admin. Use when the request mentions security, org hardening, Shield, platform encryption, field audit trail, MFA, SSO, SAML, session policy, guest user, event monitoring, GDPR, XSS, injection, why can this one user see this record, Apex managed sharing, sharing recalculation. Finds and opens the exact skill package to read; it does not contain the guidance itself.

- Skill: `pranavnagrecha/salesforce-security` (Agent Skill, multi-file: 2 files)
- Install (CLI): `npx skillmds add pranavnagrecha/salesforce-security`
- Raw SKILL.md: https://api.skillmd.com/api/skills/pranavnagrecha/salesforce-security/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: AI & ML
- Author: PranavNagrecha (https://skillmd.com/u/pranavnagrecha)
- Updated: 2026-09-08
- Page: https://skillmd.com/skills/pranavnagrecha/salesforce-security

---


# Salesforce security — SfSkills domain router

Platform security and compliance: org hardening, encryption, session policy, MFA, monitoring, incident response, and TROUBLESHOOTING a specific record-access denial. Designing the sharing model itself (OWD, role hierarchy, sharing rules) is salesforce-admin.

**49 skill packages** live under
`${CLAUDE_PLUGIN_ROOT}/skills/security/<slug>/SKILL.md`. They are not
loaded — reach them by path, on demand.

**Generated by `scripts/build_plugin.py`. Do not hand-edit.**

## How to find the right skill

Three mechanisms, listed in order of reliability on a fresh install.
Use the first one that is available; do not stop at a guess.

**1. The shipped roster (always works, no setup).**
Read `references/skill-index.md` next to this file. It lists every
`security` skill package with a one-line gloss, generated from
`registry/skills.json`. Scan it and pick by name.

**2. The MCP server (fast, needs the `sfskills-mcp` server connected).**
Call the `search_skill` tool with the user's phrasing and `domain: "security"`. It returns
ranked skill ids. `get_skill` then returns the package contents.

**3. The search CLI (fast, needs a locally built index).**

```bash
python3 "${CLAUDE_PLUGIN_ROOT}/scripts/search_knowledge.py" "<the user's question>" --domain security --json
```

This needs `vector_index/`, which is **not shipped** — it is gitignored
and must be built once per clone:

```bash
cd "${CLAUDE_PLUGIN_ROOT}" && python3 -m pip install -r requirements.txt && python3 scripts/build_index.py
```

If the command errors or reports `Coverage: NONE`, fall back to
mechanism 1 rather than telling the user the topic is uncovered.

**Then read the package.** Open the exact
`${CLAUDE_PLUGIN_ROOT}/skills/<domain>/<slug>/SKILL.md` the lookup
returned, plus its `references/gotchas.md` and
`references/llm-anti-patterns.md`. Do not answer from this router:
it is a map, not the territory.

## Featured entry points

Curated starting points when the request is broad or the lookup is
ambiguous. This is a shortlist, not the catalogue — the roster at
`references/skill-index.md` has all 49.

- `${CLAUDE_PLUGIN_ROOT}/skills/security/org-hardening-and-baseline-config/SKILL.md` — the baseline every org should already meet
- `${CLAUDE_PLUGIN_ROOT}/skills/security/permission-set-groups-and-muting/SKILL.md` — composing access with groups, and muting the over-grant
- `${CLAUDE_PLUGIN_ROOT}/skills/security/record-access-troubleshooting/SKILL.md` — why this user can (or cannot) see this record
- `${CLAUDE_PLUGIN_ROOT}/skills/security/platform-encryption/SKILL.md` — Shield Platform Encryption and everything it breaks
- `${CLAUDE_PLUGIN_ROOT}/skills/security/mfa-enforcement-patterns/SKILL.md` — MFA rollout without locking out integration users
- `${CLAUDE_PLUGIN_ROOT}/skills/security/xss-and-injection-prevention/SKILL.md` — output encoding, SOQL injection, and unsafe HTML in components
- `${CLAUDE_PLUGIN_ROOT}/skills/security/secure-coding-review-checklist/SKILL.md` — the review gate for Apex, LWC and callouts
- `${CLAUDE_PLUGIN_ROOT}/skills/security/event-monitoring/SKILL.md` — Event Monitoring, Shield log retention, and detecting misuse

## Decision trees

Read the tree *before* activating a skill when the request could be
solved more than one way, and cite the branch that decided it.

- `${CLAUDE_PLUGIN_ROOT}/standards/decision-trees/sharing-selection.md` — OWD vs role hierarchy vs sharing rules vs manual vs Apex managed sharing

## Rules

1. Answer from the opened `security` package, never from this router.
2. Cite the skill id and, where one applied, the decision-tree branch.
3. Never claim a topic is uncovered without pasting lookup output.
4. Never deploy to an org.


