A Cursor agent that reviews Salesforce DX source the way a platform architect would: Apex, Lightning Web Components, Aura, Flows, and metadata.
It packages:
- A skill (
/salesforce-code-review) with checklists for governors, CRUD/FLS, injection, tests, LWC XSS, and Flow bulkification - A read-only subagent (
salesforce-code-reviewer) so reviews run in their own context - A slash command (
/review-salesforce) - Rules that apply when Apex, LWC, or Flow files are in scope
BUGBOT.mdso Cursor Agent Review / Bugbot uses the same Salesforce bar
Repository: github.com/rediga/Salesforce-Code-Review-Agent
- Cursor (desktop)
- Git
- A Salesforce DX project (
sfdx-project.jsonand usuallyforce-app/) if you are installing into a project - Optional: Salesforce CLI and Code Analyzer, if you want the agent to merge scanner output into the report
Pick one path. Project install is the usual choice for a team Salesforce repo.
git clone https://github.com/rediga/Salesforce-Code-Review-Agent.git
cd Salesforce-Code-Review-AgentmacOS / Linux:
git clone https://github.com/rediga/Salesforce-Code-Review-Agent.git
cd Salesforce-Code-Review-Agent
chmod +x scripts/install.shCopies skills, the subagent, commands, and rules into that project's .cursor/ folder. Commit those files so everyone on the repo gets the same reviewer.
Windows (PowerShell):
.\scripts\install.ps1 -Target "C:\path\to\your-sfdx-project"macOS / Linux:
./scripts/install.sh Project /path/to/your-sfdx-projectThe script also adds BUGBOT.md and AGENTS.md if those files are not already present.
Then:
- Open the Salesforce DX project in Cursor.
- Command Palette → Developer: Reload Window.
- Open Agent chat and type
/review-salesforceto confirm the command appears.
Use this when you want the reviewer on every project on your machine without copying files into each repo.
Windows:
.\scripts\install.ps1 -Scope UserPluginmacOS / Linux:
./scripts/install.sh UserPluginThen:
- In Cursor Settings, allow third-party plugins / local plugin imports if your org requires it (Teams and Enterprise: an admin may need to enable Allow Local Plugin Imports).
- Command Palette → Developer: Reload Window.
- Open Customize → Plugins and confirm salesforce-code-review is listed.
Windows:
.\scripts\install.ps1 -Scope UserSkillsmacOS / Linux:
./scripts/install.sh UserSkillsThis writes:
~/.cursor/skills/salesforce-code-review/~/.cursor/agents/salesforce-code-reviewer.md
Reload the window. Invoke with /salesforce-code-review.
The most reliable team rollout is 2a: commit .cursor/ into each Salesforce DX repo.
Admins on Teams or Enterprise can also import this GitHub repo from the Cursor Dashboard → Plugins. If the import UI expects a multi-plugin marketplace manifest, use 2a or 2b instead.
Open your Salesforce DX project in Cursor (not only this agent repo). Then run a review in any of these ways.
Examples:
Review this Apex class for CRUD/FLS and bulkificationReview the current branch against main as a Salesforce code reviewReview PR 1234 for Salesforce security issues/review-salesforce/salesforce-code-review
Keep the skill on for the whole session by using it as a Custom Mode (Windows: Alt+Enter on the skill, macOS: Option+Enter).
| Area | Typical files | What it checks |
|---|---|---|
| Apex / triggers | .cls, .trigger |
SOQL/DML in loops, sharing, CRUD/FLS, injection, handler pattern, Named Credentials |
| LWC / Aura | lwc/, aura/ |
XSS, cacheable DML, error handling, @api mutation, a11y |
| Flows | .flow-meta.xml |
Collection DML, recursion, fault paths, user vs system context |
| Tests | *Test.cls, test*.cls |
Isolation, asserts, bulk, runAs, callout mocks |
| Security metadata | permission sets, guest access, credentials | Least privilege, secrets, Experience Cloud |
You should get a markdown report with:
- Verdict: Approve / Approve with comments / Request changes
- A table of findings sorted Critical → Low, with
file:lineand a Salesforce-specific fix - Notes on tests and residual risk
The subagent is read-only. It will not edit or deploy unless you separately ask to apply fixes.
After project install, BUGBOT.md is in the Salesforce repo root.
- Slash:
/agent-reviewor/review-bugbot - Or enable Agent Review in Cursor Settings → Agents (or Git & PRs → Pull Requests on newer Cursor)
If Salesforce Code Analyzer is installed, you can ask:
Run sf code-analyzer on the changed Apex and include those results in the review
The skill will use the CLI when it is available and will skip it when it is not.
From this clone:
git pull
.\scripts\install.ps1 -Target "C:\path\to\your-sfdx-project"For a user plugin or personal skills install, re-run the same -Scope you used originally, then reload Cursor.
| Goal | Where |
|---|---|
| Change review checklists | .cursor/skills/salesforce-code-review/references/ |
| Change when the subagent is used | .cursor/agents/salesforce-code-reviewer.md (description field) |
| Org-specific rules (naming, trigger framework) | Add another .cursor/rules/*.mdc in the DX project |
| Stop auto-invoking the skill | Set disable-model-invocation: true in the skill frontmatter |
Do not put secrets in rules or skills. Named Credential configuration belongs in the org, not in this repo.
.cursor-plugin/plugin.json Cursor plugin manifest
.cursor/skills/salesforce-code-review/
.cursor/agents/salesforce-code-reviewer.md
.cursor/commands/review-salesforce.md
.cursor/rules/ Apex, LWC, Flow, security
scripts/install.ps1 Windows installer
scripts/install.sh macOS / Linux installer
templates/AGENTS.md Copied into DX projects if missing
BUGBOT.md Agent Review / Bugbot guidance
MIT. See LICENSE.