AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Sf 2gp Security Review

skill-jiten-singh-shahi-salesforce-claude-code-sf-2gp-security-review · by jiten-singh-shahi

>-

No reviews yet
0 installs
22 views
0.0% view→install

Install

$ agentstack add skill-jiten-singh-shahi-salesforce-claude-code-sf-2gp-security-review

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-jiten-singh-shahi-salesforce-claude-code-sf-2gp-security-review)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
1mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Sf 2gp Security Review? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Salesforce 2GP Managed Package Security Review

When to Use

  • User asks for a 2GP managed package security review or AppExchange readiness assessment
  • User wants a pass/fail prediction for their managed package security review submission
  • User needs a 2GP license qualification checklist or submission readiness scoring

This skill performs a comprehensive security review of a Salesforce 2GP managed package, assesses readiness for AppExchange security review, and produces a pass/fail prediction with actionable remediation steps.

How This Skill Works

When invoked, you will:

  1. Discover the package structure (scan for Apex, LWC, objects, permissions, config)
  2. Audit every file against the security review criteria below
  3. Score each category (PASS / WARN / FAIL)
  4. Produce a structured report with an overall pass/fail prediction and remediation plan

The output is a detailed markdown report saved to the project's docs/security/ directory.


Step 1 — Package Discovery

Before auditing, build a complete inventory of the package contents. Run these searches against the project's force-app/ directory:

Apex classes:      force-app/**/classes/*.cls
Apex triggers:     force-app/**/triggers/*.trigger
LWC components:    force-app/**/lwc/*/
Aura components:   force-app/**/aura/*/
Visualforce pages: force-app/**/pages/*.page
Custom objects:    force-app/**/objects/*/
Permission sets:   force-app/**/permissionsets/*/
Custom metadata:   force-app/**/customMetadata/*/
Static resources:  force-app/**/staticresources/*/
Named credentials: force-app/**/namedCredentials/*/
Remote site settings: force-app/**/remoteSiteSettings/*/
Connected apps:    force-app/**/connectedApps/*/

Record the count of each metadata type. This inventory becomes the header of your report.


Step 2 — Security Audit Categories

Audit every file from Step 1 against 15 categories. For each category, assign a status: PASS (no issues), WARN (minor issues, unlikely to fail review), or FAIL (will likely fail AppExchange security review).

Audit criteria, grep patterns, and PASS/WARN/FAIL thresholds for all 15 categories:

@../reference/APPEXCHANGEREVIEW.md

Supporting reference for implementation patterns:

  • CRUD/FLS, sharing, injection, XSS, Named Credentials: @../reference/SECURITYPATTERNS.md
  • Sharing model details: @../reference/SHARINGMODEL.md
  • Testing standards and annotations: @../reference/TESTINGSTANDARDS.md
  • Namespace, versioning, package CLI: @../reference/PACKAGEDEVELOPMENT.md
  • Governor limits and anti-patterns: @../reference/GOVERNORLIMITS.md
  • LWC lifecycle and patterns: @../reference/LWCPATTERNS.md

Categories:

  1. CRUD/FLS Enforcement (CRITICAL — #1 failure reason)
  2. Sharing Model Enforcement
  3. SOQL/DML Injection Prevention
  4. Sensitive Data Exposure
  5. XSS and Content Security Policy
  6. External Callout Security
  7. Third-Party Library Vulnerabilities
  8. Code Coverage
  9. Namespace and Packaging Compliance
  10. Permission Model
  11. Governor Limit Safety
  12. Lightning Web Security (LWS) Compliance
  13. Connected App and OAuth Configuration
  14. Data at Rest and in Transit
  15. Documentation and Submission Readiness

Step 3 — 2GP License Qualification Checklist

After the security audit, assess readiness for 2GP licensing and AppExchange distribution. Check every item and mark as DONE, NOT DONE, or N/A.

Full checklist (Dev Hub, package config, code quality, submission, ISV, post-review):

@../reference/APPEXCHANGEREVIEW.md (section: 2GP License Qualification Checklist)


Step 4 — Pass/Fail Prediction

After completing the audit and checklist, calculate the overall score using the scoring rules and produce one of these verdicts: READY TO SUBMIT / NEEDS REMEDIATION / MAJOR REWORK NEEDED.

Scoring rules and verdict criteria:

@../reference/APPEXCHANGEREVIEW.md (section: Scoring Rules)


Step 5 — Report Output

Generate a markdown report with this structure and save it to docs/security/security-review-report.md:

# Security Review Report — [Package Name]
Generated: [Date]
Package Version: [version from sfdx-project.json]
Namespace: [namespace]

## Package Inventory
| Metadata Type | Count |
|--------------|-------|
| Apex Classes | X |
| ... | ... |

## Security Audit Results
### Overall Verdict: [READY TO SUBMIT / NEEDS REMEDIATION / MAJOR REWORK]
Score: X/15 categories passing

### Category Results
| # | Category | Status | Issues |
|---|----------|--------|--------|
| 1 | CRUD/FLS Enforcement | PASS/WARN/FAIL | Details |
| ... | ... | ... | ... |

### Critical Findings (FAIL)
[List each FAIL with file path, line number, and specific remediation]

### Warnings
[List each WARN with recommendation]

## 2GP License Qualification
[Checklist with DONE/NOT DONE status for each item]

## Remediation Plan
[Prioritized list of fixes, ordered by: automatic fails first, then likely fails, then warnings]

## Appendix: Scanner Commands
[Commands the user should run for Code Analyzer, Checkmarx, etc.]

Related

  • Scanner commands: @../reference/APPEXCHANGEREVIEW.md (section: Scanner Commands)
  • Top 20 failures: @../reference/APPEXCHANGEREVIEW.md (section: Top 20 Failures)
  • 2026 platform changes: @../reference/APPEXCHANGEREVIEW.md (section: 2026 Considerations)

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.