
Security News
Ruby's Bundler 4.0.18 Extends Cooldown to bundle lock and bundle cache
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.
sf-intelligence
Advanced tools
Salesforce Org Intelligence for AI agents: a read-only, offline, source-available MCP server and CLI. Ask about your org's metadata, dependencies, permissions, Apex and Flows — grounded in real retrieved metadata. Ships the sfi CLI and an MCP server.
A grounded, fail-closed backend for AI assistants working in one Salesforce org — answers come from the org's real metadata, not a guess.
sf-intelligence is an offline-first, read-only, MCP-first knowledge base
for a single Salesforce org. You run one sf project retrieve; it builds a local
Markdown vault and a DuckDB dependency graph, then answers questions locally
through an MCP server (the sfi.* tools) — no network egress for vault answers.
It is not a standalone chatbot: a semantic router advises — it turns each
plain-language question into a meaning-ranked shortlist of the sfi.* tools
that can answer it, tagged with the plane it needs (offline vault / opt-in live
/ hybrid) and a confidence band — and your host LLM decides which tools to
run. It fails closed: write imperatives, prompt injection, and
record-value exfiltration are refused by shape (with a read-only alternative
offered), unanswerable asks get an honest gap instead of a lookalike tool, and
genuine ambiguity gets a clarifying question instead of a guess. Terse
follow-ups resolve through an optional host-passed context.previous param —
the server itself stores no conversation state. An opt-in live read-only plane
can answer record counts and samples. MIT + Commons Clause.
Requires Node.js 20+ and an authenticated Salesforce CLI (sf).
npm install -g sf-intelligence
(or run it ad hoc with npx -y sf-intelligence … — no global install needed)
Claude Code (from your Salesforce DX repo):
claude mcp add --transport stdio --scope project sf-intelligence -- npx -y sf-intelligence mcp
Claude Desktop, or any other MCP client — add to the client's MCP config:
{
"mcpServers": {
"sf-intelligence": {
"type": "stdio",
"command": "npx",
"args": ["-y", "sf-intelligence", "mcp"]
}
}
}
From your Salesforce DX repo (the directory with sfdx-project.json):
sfi init # create the local org-kb/ vault
sfi refresh --target-org my-org-alias # retrieve metadata, build the vault
sfi status # freshness, source-tree hash, counts
sfi doctor # diagnose sf CLI / vault / auth issues
Then ask anything in your MCP client — "what fields does Account have?", "what breaks if I delete this field?", "why can't this profile see Opportunities?", "give me a tour of this org."
Read-only and offline by default. Static analysis, not runtime. No business record data in the vault. The product names its limits plainly rather than guessing.
Full guides, capabilities, the tool catalog, and configuration: https://sfi.auditforce.cloud
MIT + Commons Clause — see the LICENSE file shipped in this package, or
https://sfi.auditforce.cloud/licensing.html.
FAQs
Salesforce Org Intelligence for AI agents: a read-only, offline, source-available MCP server and CLI. Ask about your org's metadata, dependencies, permissions, Apex and Flows — grounded in real retrieved metadata. Ships the sfi CLI and an MCP server.
We found that sf-intelligence demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.