Salesforce Security Reviewer — Security agent for Claude Code
Checks sharing declarations, CRUD/FLS enforcement, and scans for exposed secrets, hardcoded Ids, or non-synthetic data.
How to install Salesforce Security Reviewer
Installs to ~/.claude/agents/armahajan24-claude-salesforce-development-demo-salesforce-security-reviewer.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/armahajan24/claude-salesforce-development-demo/HEAD/.claude/agents/salesforce-security-reviewer.md -o ~/.claude/agents/armahajan24-claude-salesforce-development-demo-salesforce-security-reviewer.md Restart Claude Code, or start a new session, for it to be picked up.
What Salesforce Security Reviewer does
name: salesforce-security-reviewer description: Checks sharing declarations, CRUD/FLS enforcement, and scans for exposed secrets, hardcoded Ids, or non-synthetic data. Use before any merge, alongside the Code Reviewer. tools: Read, Grep, Glob, Bash
You are a Salesforce Security Reviewer. You do not modify files.
Check, with pass/fail and file:line for any failure:
- Sharing keyword correctness (
with sharing/without sharing/inherited sharing). - CRUD/FLS enforcement on DML an
Alternatives in Security
- Token Auditor — Scans ui/src/ for hardcoded visual values, duplicate components, and shadcn replacement candidates; produces d 79.4k ★
- Gitnexus Security Boundary Reviewer — GitNexus security and trust-boundary reviewer 45.8k ★
- JS Analyzer — JavaScript static analysis agent for client-side security review 812 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Cerberus
Security specialist. Invoke before any deploy, when handling auth/credentials, when secrets might be exposed,
Integration Checker
Runs post-merge integration tests and security scans. Ensures all merged code works together before holistic r
Sec Reviewer
Read-only security review for ClaudeSec — verifies correctness, security risk, regressions, and that scanner c
Sf Review Agent
Final Salesforce quality gate — validate Apex, LWC, Flow against architect plan; audit security, governor limi
Hosting Security Auditor
Security review for cPanel-hosted sites - exposed secrets and .git directories, file permissions, .htaccess ha
Seraph
Static security audit of a repo's code and config (exposed secrets, missing authorisation, injection surfaces,
Related Skills
Security Sweep
Comprehensive security scanner covering OWASP Top 10 (2025), Mobile Top 10 (2024), and LLM Top 10 (2025). Scan
Skill Auditor Seguranca
Executable security and LGPD gate for AI-built projects. Scans for exposed secrets, .env leaks, Supabase servi
Verbose Activate
Show a Genesis agent's APPLIED-EXPERTISE declarations in its replies (verbose ON). Off by default; enforcement