Exposes Salesforce CLI functionality to LLM tools like Claude Desktop, allowing AI agents to execute Salesforce commands, manage orgs, deploy code, and query data through natural language
Local Onlycodefriar
Awaiting current scanNpm · 1.3.2
The selected current version does not yet have completed public verification. Unknown does not mean clean or vulnerable.
1Distribution channel
5Independently observed tools
0Linked remote endpoints
AvailableVersion intelligence
Detailed security scan evidence is not public for this MCP yet. Public identity, registry metadata, and independently observed protocol inventory remain available.
Install and connect
Installation and connection instructions are shown only when supported by retained package, repository, or endpoint evidence.
Independently scan the exact version your agents use, receive alerts when its risk changes, and investigate every finding with retained version evidence.
Independent exact-version security scans
Continuous release and vulnerability monitoring
Risk-change alerts with capability context
Historical evidence and API exports
Custom pricingContact salesTailored to your organization, integrations, data needs, and support requirements.
Current version evidence
No public current-version evidence is available yet.
Current protocol inventory
2025-06-18Negotiated protocol
Salesforce CLI MCPServer-reported name
2Capability groups
Aug 15, 2026Observed
Tools 5
Tool
Category
Annotations
Risk
sf_cache_clearClear the cached SF command metadata to force a refreshInput schema
Install the selected package version with: npm install --save-exact sf-mcp@1.3.2
What tools does Salesforce CLI MCP Server provide?
Salesforce CLI MCP Server exposed 5 tools during independent protocol observation, including sf_cache_clear, sf_cache_refresh, sf_detect_project_directory, sf_list_roots, sf_set_project_directory.
Is Salesforce CLI MCP Server secure?
The selected current version does not yet have completed public verification. Unknown does not mean clean or vulnerable.
Company and product intelligence
These internal links are derived from strong identity fields such as the implementation name, package, repository, vendor, and listing name—not generic description prose.