SalesforceBLOCK
MCP Server for interacting with Salesforce instances
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
MCP Server for Interacting with Salesforce Orgs
[](https://www.npmjs.com/package/@salesforce/mcp) [](https://opensource.org/license/apache-2-0)
Feedback
Report bugs and issues here. For feature requests and other related topics, start a Discussion here.
Documentation
For general documentation about the Salesforce DX MCP Server, see this section in the Salesforce DX Developer Guide. The docs include:
- Comprehensive overview, including details about the security features.
- Quick start guide.
- Multiple examples of configuring the server in your MCP client.
- Sample prompts for invoking the core DX MCP tools.
Overview of the Salesforce DX MCP Server
The Salesforce DX MCP Server is a specialized Model Context Protocol (MCP) implementation designed to facilitate seamless interaction between large language models (LLMs) and Salesforce orgs. This MCP server provides a robust set of tools and capabilities that enable LLMs to read, manage, and operate Salesforce resources securely.
Configure the DX MCP Server
Configure the Salesforce DX MCP Server for your MCP client by updating its associated MCP JSON file; each client is slightly different, so check your MCP client documentation for details. See MCP Client Configurations for more examples.
Here's an example for VS Code with Copilot in which you create and update a .vscode/mcp.json file in your project:
{
"servers": {
"Salesforce DX": {
"command": "npx",
"args": ["-y", "@salesforce/mcp",
"--orgs", "Df6f55474dbcdOBSERVED · 2026-09-30Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp -- npx -y @salesforce/[email protected]
{
"mcpServers": {
"mcp": {
"command": "npx",
"args": [
"-y",
"@salesforce/[email protected]"
]
}
}
}Exposed tools (15)
15 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
ApexPage | read | Root element of a Visualforce page |
BooleanLiteral | read | Boolean literal |
ClassDeclaration | read | Represents a class declaration |
Element | read | HTML element |
FunctionDeclaration | read | JavaScript function |
HtmlDocument | read | HTML document root |
IfStatement | read | Represents an if statement |
IntegerLiteral | read | Integer literal |
MethodCallExpression | read | Represents a method call |
MethodDeclaration | read | Represents a method declaration |
OutputText | read | Display text content |
StringLiteral | read | String literal |
test-tool | read | Test tool description |
test-tool-2 | read | Test tool description |
test-tool-3 | read | Test tool description |
Trust audit
BLOCKgrade D · trust 60/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- none-observed
- Shell
- declared (9 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (23)
exec(input: CreateRegexCustomRuleInput): Promise<CreateRegexCustomRuleOutput>;
exec(input: CreateXpathCustomRuleInput): Promise<CreateXpathCustomRuleOutput>;
exec(input: DescribeRuleInput): Promise<DescribeRuleOutput>;
exec(input: GetAstNodesInput): Promise<GetAstNodesOutput>;
exec(input: ListRulesInput): Promise<ListRulesOutput>;
.commitlintrc.json
.prettierrc.json
.eslintrc.cjs
.mocharc.json
.nycrc
packages/mcp/README.md
cd ../../
# Use -L flag to dereference symlinks (e.g., README.md -> ../../README.md)
cd ../../
import { ExampleMcpTool } from "../../src/tools/example_tool.js";const fileUrl = new URL(`../../data/pmd/${normalizedLanguage}-ast-reference.json`, import.meta.url);3. If successful, open the specified localhost URL in your browser. In this example it's `http://127.0.0.1:6274`:
MCP Inspector is up and running at http://127.0.0.1:6274
@commitlint/cli, @commitlint/config-conventional, @modelcontextprotocol/inspector, rimraf
@modelcontextprotocol/sdk, @salesforce/mcp-provider-api, zod, @eslint/js, @types/node, @vitest/coverage-istanbul, eslint, rimraf
@modelcontextprotocol/sdk, @salesforce/core, @salesforce/ts-types, @types/semver, semver, zod, @eslint/js, @types/node
@modelcontextprotocol/sdk, @salesforce/code-analyzer-core, @salesforce/code-analyzer-engine-api, @salesforce/code-analyzer-eslint-engine, @salesforce/code-analyzer-pmd-engine, @salesforce/code-analyze
@modelcontextprotocol/sdk, @salesforce/mcp-provider-api, @salesforce/core, @salesforce/source-deploy-retrieve, @salesforce/ts-types, zod, @eslint/js, @types/node
Gates applied: no_behavioural_pass.
f6f55474dbcdfull audit observations/trust-audit/mcp-server/salesforcecli__salesforce-12.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-30 | f6f55474dbcd | BLOCK | D | 60 | first audit |
Questions
What is the Salesforce MCP server?
MCP Server for interacting with Salesforce instances
What tools does Salesforce expose?
15 in total: 15 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Salesforce safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (60/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Salesforce need?
No credential environment variables were found in its source, so it appears to need none.
How does Salesforce run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @salesforce/mcp at 0.30.15.
How current is this page?
The grade is for one exact copy of the source (f6f55474dbcd), read on 2026-09-30. The repository is watched and re-audited when it changes.