Salesforce Cost TuningSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: salesforce-cost-tuning description: 'Analyze Salesforce license, add-on, storage, event, API, support, middleware, and operating costs from current customer evidence. Use when making cost and value decisions. Trigger with "optimize Salesforce cost".' argument-hint: "[org-or-program] [review-window]" allowed-tools: Read, Glob, Grep, WebFetch, Write, Edit version: 1.8.0 author: Jeremy Longshore <[email protected]> license: MIT tags: [saas, salesforce, cost, licensing, governance] model: inherit effort: high compatibility: Designed for Claude Code; commercial, license, retention, architecture, and workload changes require procurement, finance, platform, and business approval --- # Salesforce Cost and Value Governance ## Overview Build a dated total-cost model that connects commercial terms and technical consumption to business outcomes without inventing public prices or savings. ## Prerequisites - Current order forms, invoices, license assignments, add-ons, storage, support, and vendor or partner statements - Org usage, API and event allocations, middleware, compute, operations, incident, and migration evidence - Finance, procurement, Salesforce platform, security, data, architecture, and business owners ## Tool Discipline Use `Read`, `Glob`, and `Grep` to inspect approved repository and evidence files, `WebFetch` to re-check current first-party Salesforce documentation, and `Write` or `Edit` only for secretless plans, fixtures, configuration, and redacted receipts. ## Current Contract Salesforce editions, licenses, add-ons, storage, event delivery, API allocations, support, and partner services are customer-specific and change over time. Public documentation cannot establish one customer's price or entitlement. ## Authentication Use read-only approved billing, contract, org, and telemetry evidence. Separate commercial and technical access and do not expose user-level license, compensation, customer, or record data. ## Instructions 1. Freeze review window, currencies, orgs, products, contracts, populations, workloads, outcomes, and accountable owners. 2. Reconcile invoices and commitments with assigned and active licenses, storage, API and event usage, add-ons, support, middleware, compute, and labor. 3. Normalize time periods and currencies while preserving source, effective date, allocation method, and confidence. 4. Identify unused or mismatched assignments, duplicate capability, retention growth, event or API pressure, support load, and architectural overhead. 5. Model bounded scenarios with commercial assumptions, technical effects, business impact, security and data risk, reversibility, and confidence. 6. Present license, contract, retention, integration, scheduling, or architecture changes to the corresponding owners. 7. Canary reversible operational changes, reconcile savings and outcomes, and never claim savings until invoices and service quality confirm them. ## Approval Boundaries Do not remove licenses, change contracts, delete data, reduce support, throttle business-critical work, or re-architect integrations without owners. ## Output Return the reconciled baseline, dated sources, allocation model, anomalies, scenarios, assumptions, approvals, canary evidence, realized-versus-forecast result, and review date. ## Error Handling | Condition | Response | |---|---| | Invoice and org inventory disagree | Preserve both and route reconciliation to finance, procurement, and the platform owner. | | Scenario relies on undocumented pricing or entitlement | Mark it invalid until current customer terms are obtained. | | Nominal savings degrade compliance or business outcomes | Reject or redesign the scenario regardless of headline cost. | ## Example A redacted completion receipt might look like this: ```text window=FY2026-Q3; sources=contract+invoice+org+ops; reconciliation=exact; scenarios=4; approved=1; savings=unrealized ``` ## Resources - [Salesforce REST limits](https://developer.salesforce.com/docs/platform/api-rest/guide/resources-limits.html) - [Salesforce release notes](https://help.salesforce.com/s/articleView?id=release-notes.salesforce_release_notes.htm) ## Next Steps Run the workflow first in the lowest-risk authorized org and preserve its redacted receipt. Schedule a review against the next Salesforce seasonal release and the customer change calendar.
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__salesforce-cost-tuning.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Salesforce Cost Tuning skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Salesforce Cost Tuning safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Salesforce Cost Tuning access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Salesforce Cost Tuning work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.