vulkro-sf mcp serve
Run Vulkro for Salesforce as a Model Context Protocol server, so Claude Code, Claude Desktop, Cursor, Windsurf, Continue, VS Code's MCP client and any other JSON-RPC 2.0 MCP host can call the Salesforce scanner as a tool.
vulkro-sf mcp serve # stdio transport (default)
vulkro-sf mcp serve --port 9101 # SSE transport on http://127.0.0.1:9101/sse
| Flag | Description |
|---|---|
--port <PORT> | Bind an SSE transport on 127.0.0.1:<PORT> instead of stdio. Clients POST JSON-RPC requests to /messages and read responses from GET /sse. Most hosts use stdio. |
-v, -vv | Debug or trace logging on stderr (only when RUST_LOG is unset). |
Exit codes: 0 served and shut down cleanly; 2 error (bad transport,
port in use, internal crash).
What stays on your machine
The local tools analyse your code entirely on this machine and never
write to it. The sf_org_* tools read the org through your own
authenticated sf CLI; the OAuth token never leaves that CLI, and
nothing is sent to Vulkro. Only the sf_cloud_* tools leave the
machine, and only to the Vulkro Cloud workspace you connected. No tool
modifies source code or writes org configuration.
Local tools
Every language and every code check is Free. The Tier column names the Pro capability a tool needs, if any.
| Tool | What it does | Inputs | Tier |
|---|---|---|---|
sf_scan_project | Full scan of an SFDX project or retrieved metadata folder (Apex, LWC, Aura, Flow, Visualforce, metadata), in the shape vulkro-sf scan -f json emits. Every confidence tier is included, so check each finding's confidence. | path | Free |
sf_scan_metadata_only | Metadata-only scan, for folders or retrieved org snapshots with no Apex source. Returns the findings array. | path | Free |
sf_list_checks | The built-in check catalogue: id, name, category, kind (org or code) and default severity. Static data: no scan, no network. | category?, kind? (org | code), verbose? | Free |
sf_antipatterns | The per-file Well-Architected anti-pattern scan over Apex source (id, pillar, file, line, detail, remediation). Cross-method rules surface through sf_scan_project instead. | path, exclude_namespace? | Pro (sf-antipatterns) |
sf_code_graph | Ranked Apex method graph without a full scan: map (default), impact (blast radius), callers, callees. Code structure only; reach counts are a floor. | path, mode?, symbol? (Class.method), max_symbols?, max_tokens? | Pro (sf-maps) |
sf_assess_change | Before an edit, pass symbol for its blast radius, the tests that reach it, and its findings. After an edit, omit symbol to assess the diff against base (default HEAD, the uncommitted change), with a verdict. Read-only. | path, symbol?, base? | Pro (sf-impact) |
sf_run_compliance_report | Scan path and roll the findings up against a compliance pack: pci, hipaa, soc2, nist-ssdf, nist-800-53 (alias stateramp), iso27001, cis-v8, cwe-top25, gdpr, owasp-asvs. target_org only labels the report header. | framework, path?, target_org? | Pro (sf-compliance) |
sf_org_perms | Live org: over-privileged Modify All Data / View All Data / Author Apex grants (SF-PERM-001) and dormant privileged accounts (SF-PERM-002). | target_org | Pro (sf-live-org) |
sf_org_effective_perms | Live org: the effective object, field and permission-set access users hold now (SF-OBJ-PERM-001, SF-FIELD-PERM-001, SF-PERM-ASSIGN-001). | target_org | Pro (sf-live-org) |
sf_org_session | Live org: session idle timeout, IP-lock binding and high-assurance step-up (SF-SESSION-LIVE-001 to 003). | target_org | Pro (sf-live-org) |
sf_org_mfa | Live org: MFA enforcement for all users, for privileged users, and the API / integration-user gap (SF-MFA-001 to 003). | target_org | Pro (sf-live-org) |
sf_org_health_check | Live org: the Security Health Check score and its failing controls (SF-HEALTH-CHECK-001). | target_org | Pro (sf-live-org) |
target_org is an org alias or username known to sf org login.
A Free-tier call to a Pro tool does not stop the server: the call fails
with JSON-RPC error -32001 (License required) and a data object
carrying reason: "pro_required", the capability id and a message. See
Licensing.
Vulkro Cloud workspace tools
These fifteen tools work your Vulkro Cloud for Salesforce
workspace through the connection vulkro-sf cloud connect
saved (or VULKRO_SF_CLOUD_URL and VULKRO_SF_CLOUD_TOKEN). They need no
licence of their own; what you can do is set by your workspace role. They
use the network, so they are refused when VULKRO_OFFLINE is set. They
change workspace triage state only (proposals, assignment, review),
never source and never a Salesforce org.
An org argument takes the org label, an unambiguous prefix of it, or
its id. A finding is named by its fingerprint (fp_...) or its issue key
(VK-123).
| Tool | What it does | Inputs |
|---|---|---|
sf_cloud_connect_status | The workspace URL, who this machine is signed in as, and their role and rights. When not connected, how to connect. | none |
sf_cloud_orgs | The workspace's orgs, with queue counts (to triage, open, pending) and the last scan. | none |
sf_cloud_todo | What to fix: the ranked triage queue as compact rows. Views: to_triage (default), open, pending, suppressed, resolved, mine, all. At most 50 rows per call; page with offset. | view?, org?, severity?, risk?, rule?, q?, limit?, offset? |
sf_cloud_finding | One finding: message, remediation, state, review history and, for code findings, the engine's trace hops. An empty trace means not established, never safe. | fingerprint, evidence? |
sf_cloud_triage | Set or propose a state. new, in_progress and fixed apply at once; false_positive and accepted_risk need a reason and go to a person for approval. An assistant passes source: "ai" and its model name in source_detail. | fingerprint, state, reason?, expires_at?, source?, source_detail? |
sf_cloud_review | The review queue: list (default), approve, reject (needs a note) or withdraw your own pending proposal. | action?, id?, note?, status? |
sf_cloud_assign | Assign a finding to me, a member's user id, or none. | fingerprint, assignee |
sf_cloud_rules | Read-only rules: list (counts, noisy rules, policies) or get one rule with its findings and policy history. | action?, rule_key?, org? |
sf_cloud_rule_policy | Rule policy: list, get, or propose a mode (enforced, advisory, off), severity and org or file scope. Proposals go to a rules approver. | action?, rule_key?, org?, mode?, severity?, scope_connection_id?, scope_pattern?, reason?, expires_at? |
sf_cloud_custom_rules | Custom rules: list, get, test a posture definition against each org's latest scan (read-only), create a posture or code rule, or change its status. Create and status changes are proposals for a rules approver. | action?, rule?, kind?, rule_key?, title?, description?, severity?, definition?, yaml?, status?, org?, reason? |
sf_cloud_settings | The workspace triage settings (read-only): self-approval, automatic approval of AI verdicts, and whether scans close issues automatically. | none |
sf_cloud_scan | start a cloud scan of an org (returns scan_id) or read its status: queued, running, succeeded, failed. | action, org_id?, scan_id? |
sf_cloud_fix_plan | Map a finding to your local SFDX project: file and line, a code window, the remediation, the trace hops, a detector-verified auto-fix command when one exists, and the steps. For an org finding, the metadata change to make in the project. | fingerprint, path |
sf_cloud_verify | Re-run the local scan and report whether the finding's rule still fires in its file. With mark_fixed: true and the finding gone, mark it fixed; the next cloud scan confirms it. | fingerprint, path, mark_fixed? |
sf_cloud_verify_org | Start a workspace scan of the issue's org, wait for it (default 600 s, 60 to 1800), and report still_reported, no_longer_reported, closed_by_scan or not_rechecked. Use it after the metadata change is deployed; mark_fixed: true marks it fixed. | fingerprint, org?, mark_fixed?, timeout_secs? |
Set up in Claude Code and Cursor
Claude Code
claude mcp add vulkro-sf -- vulkro-sf mcp serve
The skill installer's Claude Code option adds the vulkro-sf skill
alongside the vulkro one:
curl -fsSL https://dist.vulkro.com/skill-install.sh | bash -s -- --agent claude-code
Cursor and other MCP hosts
Add the server to ~/.cursor/mcp.json (Claude Desktop, Windsurf and
Continue take the same shape; see vulkro mcp serve
for each host's file):
{
"mcpServers": {
"vulkro-sf": {
"command": "vulkro-sf",
"args": ["mcp", "serve"]
}
}
}
VS Code agent mode
The VS Code extension
registers this server for the editor's agent automatically, launched with
VULKRO_OFFLINE=1. The local tools work there; the sf_cloud_* tools
are refused under that setting, so register vulkro-sf mcp serve in your
host yourself to use them.
Environment variables
| Variable | Effect |
|---|---|
VULKRO_SF_MCP_LOG=1 | Per-request trace lines on stderr. Off by default so the stdio JSON-RPC stream stays free of side-band output. |
VULKRO_SF_CLOUD_URL, VULKRO_SF_CLOUD_TOKEN | The workspace address and token for the sf_cloud_* tools, instead of the saved connection. |
VULKRO_OFFLINE | Refuses the sf_cloud_* tools; local scans keep working. |
Related
vulkro-sf cloud: the same workspace actions from the terminal.vulkro-sf checks: the catalogue behindsf_list_checks.vulkro mcp serve: the MCP server for application code.