salesforce-deployment-guard
Enables analyzing Salesforce deployment logs, validating metadata manifests, assessing permission risks, and generating remediation plans through deterministic, local-only rules.
README
Salesforce Deployment Guard MCP
A local-only Model Context Protocol server that turns Salesforce-style deployment evidence into structured findings and remediation steps.
This is a clean-room portfolio project. It uses deterministic rules and synthetic examples—no Salesforce org, credentials, LLM, telemetry, or network access.
Tools
| Tool | Purpose |
|---|---|
analyze_deployment_log |
Classifies missing metadata, invalid references, Apex test failures, permission failures, malformed XML, and unknown evidence. |
validate_metadata_manifest |
Detects missing dependencies, duplicates, invalid names, self-dependencies, and cycles. |
assess_permission_risk |
Flags broad system permissions, object Modify All, duplicate changes, and write-without-read combinations. |
build_remediation_plan |
Turns findings into a deterministic, priority-ordered checklist. |
Every tool is read-only and returns both human-readable text and structured JSON.
Quick start
Requirements: Node.js 20.19 or newer.
git clone https://github.com/qpulce-dev/salesforce-deployment-guard-mcp.git
cd salesforce-deployment-guard-mcp
npm ci
npm run verify
npm run build
Connect an MCP client
Codex CLI:
codex mcp add salesforce-deployment-guard -- node "/absolute/path/to/salesforce-deployment-guard-mcp/dist/server.js"
Claude Desktop-compatible configuration:
{
"mcpServers": {
"salesforce-deployment-guard": {
"command": "node",
"args": [
"/absolute/path/to/salesforce-deployment-guard-mcp/dist/server.js"
]
}
}
}
Restart the client after changing its MCP configuration.
Live MCP transcript
Captured from a real MCP client connected to the built server over stdio:
connected: salesforce-deployment-guard-mcp
tools: analyze_deployment_log, validate_metadata_manifest, assess_permission_risk, build_remediation_plan
call: analyze_deployment_log
arguments: {"log":"Error: no CustomField named Demo__c.Region__c found"}
{
"status": "issues_found",
"findings": [
{
"code": "SF_MISSING_METADATA",
"category": "missing_dependency",
"severity": "error",
"evidence": "Error: no CustomField named Demo__c.Region__c found",
"likelyCause": "A referenced metadata component is absent from the deployment set or target org.",
"nextChecks": [
"Confirm the referenced component exists in source control.",
"Add the dependency to the deployment manifest before its consumer."
]
}
]
}
The fixtures/ directory contains additional synthetic inputs.
Architecture
MCP client
-> Zod input schema
-> small tool handler
-> deterministic domain function
-> structured JSON + concise text
src/server.tsregisters tools and owns stdio startup.src/domain/contains pure diagnostic and planning logic.src/tools/result.tsformats stable MCP responses.tests/covers domain behavior, privacy rules, and a real stdio MCP handshake.fixtures/contains synthetic examples only.
Verification
npm run verify
That command runs formatting, ESLint, strict TypeScript checks, 39 tests, a production build, and the privacy scan. The MCP smoke test launches the built server, negotiates a client connection, lists all four tools, and calls one tool.
CI runs the same verification on Node.js 20.19 and 22.
Privacy and security
- No runtime network calls.
- No data persistence or telemetry.
- No environment variables or credentials required.
- Inputs are bounded before analysis.
- Errors do not return stack traces or local paths.
- Included examples use names such as
Demo__candDemo_Access. - The privacy scanner reports only file and rule identifiers, never matched secret text.
For an extra local organization-name check:
PRIVATE_ORG_NAMES="Private Org One,Private Org Two" npm run privacy:scan
Do not paste real production logs into public issues, commits, or fixtures.
Limits
This server provides deterministic review guidance. It does not connect to Salesforce, validate against a live org, replace a security review, or guarantee deployment success. Unknown evidence stays classified as unknown.
License
MIT © 2026 Queanu Pulce
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。