Atlas / MCP servers / taurgis / SFCC Dev

SFCC DevBLOCK

mcp/taurgis/sfcc-dev

Supercharge your Salesforce B2C Commerce Cloud development with AI-powered documentation access, real-time log analysis, and intelligent best practices guidance

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
62 59r · 3w · 0d
Transport
stdio
License
MIT
Stars
28
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://badge.fury.io/js/sfcc-dev-mcp) [](https://opensource.org/licenses/MIT)

An AI-powered Model Context Protocol (MCP) server that provides comprehensive access to Salesforce B2C Commerce Cloud development tools, documentation, and runtime diagnostics.

✨ Key Features

  • 🔍 Complete SFCC Documentation Access - Search and explore all SFCC API classes and methods
  • 🏗️ SFRA Documentation - Enhanced access to Storefront Reference Architecture documentation
  • 🧱 ISML Template Reference - Complete ISML element documentation with examples and usage guidance
  • 📊 Log Analysis Tools - Real-time error monitoring, debugging, and job log analysis for SFCC instances
  • ⚙️ System Object Definitions - Explore custom attributes and site preferences
  • 🧪 Script Debugger - Execute and inspect script-debugger endpoints in credentialed mode, including custom trigger URLs/paths for non-default storefront routes
  • 🚀 Cartridge Generation - Automated cartridge structure creation with workspace-bound path safety (writes stay inside workspace roots, or current working directory fallback when roots are unavailable; home-directory fallback is blocked)
  • 🧩 Agent Skill Bootstrap - Install or merge AGENTS.md and bundled skills into the current project or a temp directory for AI assistants
  • ✅ Tool Argument Validation - Runtime schema validation enforces required fields, type checks, enum constraints, integer/numeric bounds, and strict unknown-key checks for object schemas (top-level and nested) before handler execution
  • ⏱️ MCP Progress + Cancellation - Tool calls honor request cancellation signals and emit out-of-band notifications/progress updates when clients provide a progressToken

🚀 Quick Start

Option 1: Documentation-Only Mode (No SFCC credentials needed)

{
"mcpServers":
Read from source at commit 37d925b6f7d6OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add sfcc-dev-mcp -- npx -y [email protected]
03

Exposed tools (62)

59 read · 3 write · 0 destructive.

ToolRiskDescription
activate_code_versionreadActivate a code version (deactivates current). Use for code-switch fixes, SCAPI endpoint issues, or deployment conflicts. Only inactive versions can be activated.
disable_agent_syncwriteCreates or updates mcp-dev.json in the project root with {
fallbackreadfallback element
generate_cartridge_structurereadGenerate a complete SFCC cartridge with proper directory structure, configurations, and boilerplate files. Creates files directly in the target directory.
get_available_sfra_documentsreadList all SFRA documentation including Server, Request, Response, QueryString, render module, and 26+ model docs (cart, account, billing, shipping, products, pricing).
get_code_versionsreadList all code versions on the SFCC instance. Use for deployment management, identifying active version, or preparing code-switch fixes.
get_isml_categoriesreadGet all ISML element categories with descriptions and counts.
get_isml_elementreadGet detailed documentation for an ISML element including syntax, attributes, examples, and use cases.
get_isml_elements_by_categoryreadGet ISML elements filtered by category (control-flow, output, includes, scripting, cache, decorators, special, payment, analytics).
get_job_execution_summaryreadGet execution summary for a job: timing, status, error counts, and step info. Use for monitoring job health and performance.
get_job_log_entriesreadGet job log entries by level (error/warn/info/debug/all). Unlike standard logs, job logs combine all levels in one file.
get_latest_job_log_filesreadGet recent job log files from /Logs/jobs/. Job logs contain all log levels in single files. Use for debugging custom job steps.
get_log_file_contentsreadRead full contents of a specific log file. Use for detailed analysis when you need complete error traces or full context.
get_sfcc_class_documentationreadGet the full raw documentation for an SFCC class including examples and detailed descriptions. Use when get_sfcc_class_info lacks sufficient detail.
get_sfcc_class_inforeadGet detailed information about an SFCC class including properties, methods, constants, and inheritance. Essential for understanding dw.* APIs when building controllers, scripts, templates, or REST APIs. Supports filtering by section and search within class members.
get_sfra_categoriesreadGet all SFRA document categories with counts. Use to understand documentation organization before browsing.
get_sfra_documentreadGet complete SFRA class or model documentation with properties, methods, and examples. Use for implementing controllers, middleware, or working with SFRA models.
get_sfra_documents_by_categoryreadGet SFRA documents filtered by functional area (core classes, product models, order/cart, customer, pricing, store).
get_system_object_definitionreadGet metadata for a specific system object (attribute count, group count, flags). For attribute details, use search_system_object_attribute_definitions. Does not work for Custom Objects.
get_system_object_definitionsreadGet all system object definitions with metadata (not attributes). Use to discover available objects and identify Custom Objects via the _type field.
isifreadConditional element
isloopreadLoop element
isprintreadOutput element
list_isml_elementsreadList all ISML template elements with summaries. Includes control flow (isif, isloop), output (isprint), includes (isinclude, iscomponent), scripting (isscript), and caching (iscache).
list_log_filesreadList available log files with sizes and modification dates. Use to discover available log data or check log retention.
list_sfcc_classesreadList all available SFCC dw.* classes organized by namespace. Use to explore the full API surface or find classes in a specific domain.
search_custom_object_attribute_definitionsreadSearch attribute definitions within a custom object type (user-defined objects, not system objects). Supports text search, filtering, and sorting.
search_isml_elementsreadSearch ISML elements by purpose, attribute name, or use case. Returns relevance-scored results with preview snippets.
search_job_logsreadSearch job logs for patterns, error messages, or custom logging from job steps. Essential for debugging custom job code.
search_job_logs_by_namereadFind job log files by job name (partial match supported). Use to locate logs for a specific job.
search_logswriteSearch logs for specific patterns, error messages, order numbers, user IDs, or custom identifiers. Essential for tracking specific transactions.
search_sfcc_classesreadFind SFCC classes by partial name or keyword. Use when you don
search_sfcc_methodsreadFind methods across all dw.* classes by name. Use when you know a method exists but not which class contains it.
search_sfra_documentationreadSearch across all SFRA docs for concepts or functionality. Returns relevance-scored results with categorization.
search_site_preferencesreadSearch site preferences by name, description, or type. Use to validate preference names and types when working with Site.getCurrent().getCustomPreferenceValue() or dw.system.Site.current.preferences.custom.*.
search_system_object_attribute_definitionsreadSearch attribute definitions within a system object. Supports text search, filtering by mandatory/searchable/system, and sorting. Use match_all_query to get all attributes.
search_system_object_attribute_groupsreadSearch attribute groups for a system object. Use
sfcc-cachingreadUnified caching playbook for SFCC (page cache vs custom cache vs service response cache). Use this when improving performance, reducing external calls, designing cache keys/TTLs, or debugging stale cache behavior.
sfcc-cartridge-developmentreadGuide for creating, configuring, and deploying custom SFRA cartridges in Salesforce B2C Commerce. Use this when asked to create a new cartridge, set up a cartridge structure, or work with cartridge paths.
sfcc-forms-developmentreadGuide for building, validating, securing, and persisting SFCC storefront forms (SFRA + SiteGenesis patterns). Use this when creating or troubleshooting form XML, controller handling, CSRF, and validation.
sfcc-fraud-preventionreadLayered fraud prevention playbook for Salesforce B2C Commerce developers. Use this when adding fraud signals, designing a risk scoring approach, integrating third-party tools, or hardening checkout/login against bot-driven abuse.
sfcc-hooks-registrationreadRegister SFCC hooks via cartridge package.json and hooks.json. Use when adding hooks or troubleshooting hook registration.
sfcc-isml-developmentreadSFRA-first guide for developing ISML templates in Salesforce B2C Commerce (Bootstrap 4 conventions). Use this when creating, modifying, or troubleshooting SFRA templates, decorators, components, forms, includes, and caching.
sfcc-job-developmentreadGuide for developing custom jobs in Salesforce B2C Commerce Job Framework. Use this when asked to create batch jobs, scheduled tasks, chunk-oriented processing, or task-oriented jobs.
sfcc-localizationreadGuide for localizing templates, forms, and content in Salesforce B2C Commerce. Use this when implementing multi-language support, resource bundles, locale-specific content, and internationalization features.
sfcc-localserviceregistryreadGuide for creating server-to-server integrations in Salesforce B2C Commerce using LocalServiceRegistry. Use this when asked to integrate external APIs, create HTTP services, implement OAuth flows, or configure service credentials.
sfcc-loggingreadGuide for implementing logging in Salesforce B2C Commerce scripts
sfcc-ocapi-hooksreadGuide for implementing OCAPI hooks in Salesforce B2C Commerce. Use this when asked to create OCAPI hooks, extend API endpoints, validate API requests, or modify API responses.
sfcc-ocapi-scapi-slasreadDecision guide for OCAPI vs SCAPI, and practical SLAS token lifecycle guidance (guest tokens, refresh rotation, public vs private clients, and hybrid SFRA/headless auth). Use this when planning integrations or debugging auth/rate-limit issues.
sfcc-page-designerreadGuide for creating Page Designer pages and components in Salesforce B2C Commerce
sfcc-performancereadPerformance optimization strategies for Salesforce B2C Commerce Cloud including caching, efficient data retrieval, index-friendly APIs, and job optimization. Use when asked about SFCC performance, caching strategies, or optimization.
sfcc-platform-limitsreadCheat-sheet and design patterns for surviving SFCC quotas and limits (script timeouts, HTTPClient call caps, session size, custom object quotas, file I/O restrictions, and headless rate limits). Use this when debugging enforced quota violations or designing scalable SFCC architectures.
sfcc-scapi-custom-endpointsreadGuide for developing SCAPI Custom APIs on Salesforce B2C Commerce. Use this when asked to create custom REST endpoints, api.json, schema.yaml, or script implementations.
sfcc-scapi-hooksreadGuide for implementing SCAPI hooks in Salesforce B2C Commerce. Use this when asked to create SCAPI hooks, extend Shopper API endpoints, validate API requests, or modify API responses for headless commerce.
sfcc-script-evaluationwriteGuide for using the evaluate_script tool to execute JavaScript on SFCC instances via the script debugger
sfcc-securityreadSecure coding best practices for Salesforce B2C Commerce Cloud including CSRF protection, authentication, authorization, cryptography, and secrets management. Use when asked about SFCC security, input validation, or secure coding patterns.
sfcc-sfra-client-side-jsreadGuide for extending, structuring, validating, and optimizing client-side JavaScript in SFRA storefronts. Use when asked to build AJAX flows, form validation, DOM interactions, or client-side customizations.
sfcc-sfra-controllersreadGuide for developing SFRA controllers in Salesforce B2C Commerce. Use this when asked to create controllers, extend base functionality, implement middleware chains, handle routing, or customize storefront behavior.
sfcc-sfra-modelsreadGuide for creating, extending, and customizing models within SFRA. Use this when asked to develop product models, cart models, customer models, or any JSON transformation layer in SFCC.
sfcc-sfra-scssreadBest practices for styling and theming SFRA storefronts using SCSS. Use when asked to create style overrides, theming, responsive layouts, or CSS customizations in SFCC.
sfcc-webdav-workflowsreadPractical guide for using WebDAV in Salesforce B2C Commerce Cloud for IMPEX transfers and log access. Use this when setting up WebDAV clients, debugging WebDAV permission issues, or designing automation that reads/writes files via WebDAV.
summarize_logsreadGet a health overview of all log activity with counts and key issues. Use as first step when investigating problems or for daily health checks.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (5 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
ai-instructions/skills/sfcc-localserviceregistry/SKILL.md:271
- **Auth Service (AuthTokenService.js)**: Handles the POST request to the token endpoint.
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
MEDIUMInventory / provenance · inv.binary · CWE-1104
.DS_Store
.DS_Store
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
ai-instructions/.DS_Store
.DS_Store
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/clients/base/ocapi-auth-client.ts:89
this.logger.debug(`Requesting token from: ${authUrl}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/clients/base/ocapi-auth-client.ts:131
this.logger.error(`Failed to get access token: ${message}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/config/workspace-roots.ts:439
this.logger.debug(`[WorkspaceRoots]   password: ${config.password ? '(set)' : '(not set)'}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/config/workspace-roots.ts:441
this.logger.debug(`[WorkspaceRoots]   client-secret: ${config['client-secret'] ? '(set)' : '(not set)'}`);
LOWInventory / provenance · inv.hidden_file · CWE-1104
.DS_Store
.DS_Store
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
ai-instructions/.DS_Store
.DS_Store
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
tests/servers/sfcc-mock-server/server.js:121
console.log(`   Client Secret: ${this.config.validCredentials.clientSecret}`);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/clients/base/abstract-documentation-client.ts:13
import { CacheManager } from '../../utils/cache.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/clients/base/abstract-documentation-client.ts:14
import { Logger } from '../../utils/logger.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/clients/base/abstract-documentation-client.ts:20
} from '../../utils/markdown-utils.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/clients/base/abstract-documentation-client.ts:21
import { buildCategoryList, CategoryInfo } from '../../utils/category-utils.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/clients/base/http-client.ts:8
import { Logger } from '../../utils/logger.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
docs-site-v2/package.json
vitepress
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
tests/servers/sfcc-mock-server/package.json
cors, express
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs-site-v2/security/index.md:8
This server is designed for local, single-developer use. It does not store credentials on disk or transmit them to third-party services.
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/dw_customer/CustomerMgr.md:601
**Description:** Searches for a single profile instance. The search can be configured using a simple query language, which provides most common filter and operator functionality. The identifier for an
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/dw_customer/CustomerMgr.md:644
**Description:** Searches for profile instances. The search can be configured with a map, which key-value pairs are converted into a query expression. The key-value pairs are turned into a sequence of
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/dw_customer/CustomerMgr.md:689
**Description:** Searches for a single profile instance. The search can be configured using a simple query language, which provides most common filter and operator functionality. The identifier for an
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
ai-instructions/skills/sfcc-isml-development/references/REMOTE-INCLUDES.md:11
| Data Scope | Full access to parent `pdict` & variables | Isolated – only URL query params available |
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/dw_system/PipelineDictionary.md:12
The class provides access to the values in the pipeline dictionary. You use dynamic properties to access values, such as pdict.myvalue or pdict['myvalue']; The class is used in two different contexts,
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/dw_customer/CustomerPasswordConstraints.md:12
Provides access to the constraints of customer passwords. An instance of this class can be obtained via CustomerMgr.getPasswordConstraints().
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/dw_customer/Profile.md:15
The class represents a customer profile. It also provides access to the customers address book and credentials. Note: this class handles sensitive security-related data. Pay special attention to PCI D
Why it matters. asks the agent to read credentials

Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.

Audited 2026-10-08 · audit v0.4.1 · source sha 37d925b6f7d6full audit observations/trust-audit/mcp-server/taurgis__sfcc-dev.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0837d925b6f7d6BLOCKD69first audit
06

Questions

What is the SFCC Dev MCP server?

Supercharge your Salesforce B2C Commerce Cloud development with AI-powered documentation access, real-time log analysis, and intelligent best practices guidance

What tools does SFCC Dev expose?

62 in total: 59 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is SFCC Dev safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does SFCC Dev need?

It reads SFCC_CLIENT_SECRET and SFCC_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does SFCC Dev run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as sfcc-mock-server at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (37d925b6f7d6), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement