npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

sf-intelligence

v0.3.2

Published

Salesforce Org Intelligence for AI agents: a read-only, offline, source-available MCP server and CLI. Ask about your org's metadata, dependencies, permissions, Apex and Flows — grounded in real retrieved metadata. Ships the sfi CLI and an MCP server.

Downloads

1,312

Readme

sf-intelligence

A grounded, fail-closed backend for AI assistants working in one Salesforce org — answers come from the org's real metadata, not a guess.

sf-intelligence is an offline-first, read-only, MCP-first knowledge base for a single Salesforce org. You run one sf project retrieve; it builds a local Markdown vault and a DuckDB dependency graph, then answers questions locally through an MCP server (the sfi.* tools) — no network egress for vault answers. It is not a standalone chatbot: a semantic router advises — it turns each plain-language question into a meaning-ranked shortlist of the sfi.* tools that can answer it, tagged with the plane it needs (offline vault / opt-in live / hybrid) and a confidence band — and your host LLM decides which tools to run. It fails closed: write imperatives, prompt injection, and record-value exfiltration are refused by shape (with a read-only alternative offered), unanswerable asks get an honest gap instead of a lookalike tool, and genuine ambiguity gets a clarifying question instead of a guess. Terse follow-ups resolve through an optional host-passed context.previous param — the server itself stores no conversation state. An opt-in live read-only plane can answer record counts and samples. MIT + Commons Clause.

Upgrading to 0.3.0 (breaking)

0.3.0 changes defaults. If you are coming from 0.2.x, read this before upgrading — full detail in CHANGELOG.md.

  • SFI_TOOL_PROFILE now defaults to core. 19 tools are advertised and directly invokable; the other ~190 are reached with sfi.run_analysis { name: 'sfi.<tool>', args }. Set SFI_TOOL_PROFILE=full to restore the previous advertise-and-invoke-everything behavior.
  • liveEnabled: true no longer opens the live plane. Grant standing consent with sfi.live_consent { grant: true } (OrgId + principal bound, scoped, 7-day expiry) or set SFI_LIVE_PLANE_ENABLED=1.
  • Existing on-disk live grants stop working — v1 consent records are dropped. Re-grant once.
  • The update check is now opt-in. Set SFI_UPDATE_CHECK=1 (default network mode is off).
  • Every success envelope gains a contentPolicy block (~280 bytes) marking org metadata as untrusted data for hosts.

Install

Requires Node.js 20+ and an authenticated Salesforce CLI (sf).

npm install -g sf-intelligence

(or run it ad hoc with npx -y sf-intelligence … — no global install needed)

Register the MCP server

Claude Code (from your Salesforce DX repo):

claude mcp add --transport stdio --scope project sf-intelligence -- npx -y sf-intelligence mcp

Claude Desktop, or any other MCP client — add to the client's MCP config:

{
  "mcpServers": {
    "sf-intelligence": {
      "type": "stdio",
      "command": "npx",
      "args": ["-y", "sf-intelligence", "mcp"]
    }
  }
}

First run

From your Salesforce DX repo (the directory with sfdx-project.json):

sfi init                               # create the local org-kb/ vault
sfi refresh --target-org my-org-alias  # retrieve metadata, build the vault
sfi status                             # freshness, source-tree hash, counts
sfi doctor                             # diagnose sf CLI / vault / auth issues

Then ask anything in your MCP client — "what fields does Account have?", "what breaks if I delete this field?", "why can't this profile see Opportunities?", "give me a tour of this org."

Boundaries

Read-only and offline by default. Static analysis, not runtime. No business record data in the vault. The product names its limits plainly rather than guessing.

Documentation

Full guides, capabilities, the tool catalog, and configuration: https://sfi.auditforce.cloud

License

MIT + Commons Clause — see the LICENSE file shipped in this package, or https://sfi.auditforce.cloud/licensing.html.