Platform Apex Anonymous Run

作者 forcedotcom3c15867bdb9d無授權條款1K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫昨天更新

Runs anonymous Apex against the connected org (.apex file or pasted snippet), capturing the debug log, surfacing errors. Triggers on "run this anonymous apex", "execute this script against my org", "what does this code return", or "execute scripts/foo.apex". Wraps scripts in savepoint+rollback; warns before running in production. DO NOT TRIGGER for authoring .cls/.trigger files (platform-apex-generate), Apex unit tests (platform-apex-test-run), or debug-log analysis (platform-apex-logs-debug).

AI 產生的概覽

透過 sf CLI 對已連線的 Salesforce 組織執行匿名 Apex,擷取偵錯記錄並回報錯誤。

功能
使用 sf apex run --file 對已連線的 Salesforce 組織執行來自 .apex 檔案或貼上片段的匿名 Apex,並解析 JSON 回應。它會回報編譯錯誤、執行階段例外、調控器限制訊號與偵錯記錄輸出,並可將驗證類指令碼包在儲存點與回復中。它會在對正式組織執行前提出警告,並將撰寫、單元測試與深度記錄分析交給相關技能處理。
適用情境
適用於開發人員想對 Salesforce 組織執行匿名 Apex 指令碼或貼上的片段,並查看傳回結果的情況。也適合需要回復變更的驗證類執行,以及檢查片段中的編譯或執行階段錯誤。
執行需求
需要 Salesforce CLI(sf,2.0.0 或更新版本)以及已通過驗證的目標組織,組織從設定中解析或由開發人員提供。需要連線至該組織的網路存取。僅為說明文件,不隨附指令碼。

platform-apex-anonymous-run

Run anonymous Apex against the connected Salesforce org via sf apex run --file, capture the debug log, and narrate compile-time and runtime outcomes back to the developer.

This is the agent-side equivalent of VS Code's Execute Anonymous Apex (document and selection) commands.

This skill is runtime, not generation — for authoring .cls / .trigger files use platform-apex-generate; for running Apex unit tests use platform-apex-test-run; for deep debug-log analysis (governor breakdowns, SOQL-in-loop detection) hand off to platform-apex-logs-debug.


Tool Restrictions

Use ONLY the Bash tool to execute sf apex run, and the Write tool to stage snippet temp files. Do NOT use MCP tools for execution.


Anonymous Apex is NOT read-only

Anonymous Apex executes with the running user's permissions and can perform DML, callouts, and platform events. Treat every invocation as a write unless the developer has stated otherwise.

  • Verification-style scripts (preferred for "test this"): wrap the body in a savepoint + rollback so org state is untouched:

    apex
    Savepoint sp = Database.setSavepoint();try {    // ... code under test ...} finally {    Database.rollback(sp);}
  • Production org heads-up: if the resolved <alias> points at a production org (no scratch/sandbox markers in sf org display --json), surface a clear warning before running. This is informational only — there is no automated block. Always wait for an explicit "yes, run it" before executing destructive scripts in prod.

  • Never run anonymous Apex you did not generate or have not been shown — if the developer pastes a snippet, echo it back and confirm before executing.


Workflow

Step 1 — Identify the target org

Resolve the active org alias from configuration. If target-org is set, the --target-org flag may be omitted from the command, but always log which alias was used in the report.

bash
sf config get target-org --json

Throughout this skill, <alias> is the resolved alias or username. If no target-org is set, ask the developer; do not silently default. If the org is not authenticated, re-authenticate with sf org login web or switch orgs with the dx-org-switch skill.

Step 2 — Resolve the input mode

ModeWhenAction
File modeDeveloper points at an existing path ending in .apex (or any path they specify)Run sf apex run --file <path> directly
Snippet modeDeveloper pastes Apex code into the conversationWrite to .sfdx/tmp/anon-<unix-ts>.apex first, then run sf apex run --file <tmp-path>

Why a temp file for snippets, instead of an inline flag? The current sf apex run CLI only supports --file (and interactive stdin). It does not expose an --apex-code flag. Even where inline code is supported by other tooling, multi-line Apex passed inline runs into shell-escaping pitfalls (single quotes in string literals, backslashes, embedded $). Writing to a temp file is the only reliable path for arbitrary snippets.

Verify CLI flags before deviating:

bash
sf apex run --help

Supported flags (as of writing): --file/-f, --target-org/-o, --api-version, --json, --flags-dir. Do not invent flags — if the task asks for something not listed, surface that to the developer rather than guessing.

Step 3 — Set up trace flags (for useful logs)

sf apex run returns a debug log only if a TraceFlag is active for the running user (or a streaming tail is attached). Recommended path — let the developer tail logs in another terminal:

bash
sf apex tail log --target-org <alias> --color

This auto-creates a short-lived TraceFlag for the running user and streams logs as anonymous Apex executes. Mention this in the report so the developer can copy/paste it.

If no trace flag is set up, sf apex run will still execute the code and return compile/runtime status — only the debug log body will be missing or sparse.

Step 4 — Snippet mode: write the temp file

Only applies when the input is a pasted snippet:

bash
mkdir -p .sfdx/tmpTS=$(date +%s)# write the snippet content to .sfdx/tmp/anon-${TS}.apex via the Write tool, NOT via shell heredoc

Use the agent's Write tool (not a heredoc) so the snippet is preserved verbatim — heredocs subject the content to additional shell expansion. Echo the resolved temp path to the developer in the report. Do not auto-clean the temp file after execution — leave it under .sfdx/tmp/ for inspection. The .sfdx/ directory is conventionally gitignored.

Step 5 — Execute

bash
sf apex run --file <path> --target-org <alias> --json
  • Always pass --json. Human-format output conflates compile vs runtime errors.
  • If target-org is already configured, --target-org may be omitted, but log the alias used.
  • The command exits non-zero on compile errors. Capture both stdout and the parsed JSON.

Step 6 — Parse the JSON response

The sf apex run --json response shape (relevant fields):

json
{  "status": 0,  "result": {    "compiled": true,    "success": true,    "compileProblem": "",    "exceptionMessage": "",    "exceptionStackTrace": "",    "line": -1,    "column": -1,    "logs": "...full debug log text..."  }}

Decision tree:

compiledsuccessMeaningSurface
false—Compile failurecompileProblem, line, column, the offending source line
truefalseRuntime exceptionexceptionMessage, exceptionStackTrace, plus log tail
truetrueSuccessWhatever the script printed via System.debug (extracted from logs)

status !== 0 (top-level) means the CLI itself failed (not authenticated, file not found, network). Surface the raw error and stop.

Step 7 — Surface the debug log

  • Short logs (< ~200 lines): inline the log body in the report between fenced code blocks.
  • Large logs: write the log to .sfdx/tmp/anon-<ts>.log and report the path. Include the last 30 lines inline as a tail summary.
  • Empty / missing log: likely no active TraceFlag. Surface the Step 3 setup hint and proceed with whatever compile/runtime status was returned.

Highlight these patterns when present in the log:

PatternWhy it matters
LIMIT_USAGE_FOR_NS linesGovernor consumption snapshot — flag SOQL/DML/CPU near-limit
EXCEPTION_THROWNUnhandled exception within the anonymous block
FATAL_ERRORUnrecoverable error — show the full trailing block
SOQL_EXECUTE_BEGIN count > 1 inside a loopSOQL-in-loop hint (hand off to platform-apex-logs-debug)
DML_BEGIN count highUnbatched DML hint

Do not attempt full log parsing here — surface signals only, then hand off to platform-apex-logs-debug for deep analysis.

Step 8 — Report

text
Anonymous Apex run: <one-line summary — file or snippet, success or failure>Org: <alias>  (mode: scratch | sandbox | production)Source: <file path or temp path for snippet>Compile: success | <error + line:column>Runtime: success | <exception type + message>Limits: <CPU=x/10000ms, SOQL=y/100, DML=z/150>  (only when log includes LIMIT_USAGE_FOR_NS)Log: <inline | path .sfdx/tmp/anon-<ts>.log>Rollback: applied | not applied | n/aNext: <suggested follow-up>

Examples

Example 1 — File mode

"Run scripts/seed-test-data.apex against my default org."

  1. Resolve <alias> from sf config get target-org --json.
  2. Confirm the file exists; if not, stop and surface file not found.
  3. Run sf apex run --file scripts/seed-test-data.apex --target-org <alias> --json.
  4. Parse JSON. Report compile/runtime status, log tail, and org mode.
  5. Suggest: "If this seeded real data and you'd like to verify without persisting, re-run with the rollback wrapper (snippet mode)."

Example 2 — Snippet mode (read query)

"Execute System.debug([SELECT count() FROM Account]); and tell me the count."

  1. Resolve <alias>.
  2. Echo the snippet back; confirm.
  3. Write the snippet to .sfdx/tmp/anon-<ts>.apex (Write tool).
  4. Run sf apex run --file .sfdx/tmp/anon-<ts>.apex --target-org <alias> --json.
  5. Parse result.logs; extract the USER_DEBUG line for the count.
  6. Report: "Account count = N. Source: .sfdx/tmp/anon-<ts>.apex (kept for reference)."

Example 3 — Verification with rollback

"Test that this Apex correctly upserts a Contact, then rollback."

  1. Resolve <alias>. If prod, surface a heads-up before running.

  2. Wrap the developer's snippet:

    apex
    Savepoint sp = Database.setSavepoint();try {    // ---- developer snippet begins ----    Contact c = new Contact(LastName = 'Smoke', Email = '[email protected]');    upsert c Email;    System.debug('Upserted: ' + c.Id);    // ---- developer snippet ends ----} finally {    Database.rollback(sp);    System.debug('Rolled back savepoint.');}
  3. Write to .sfdx/tmp/anon-<ts>.apex, execute, parse JSON.

  4. Report compile/runtime status, the upserted Id from the log, and Rollback: applied.


Failure Modes

SymptomCauseRecovery
No authorization information found for ...Org not authenticated, or alias is wrongRun sf org list --json; re-auth with sf org login web or use dx-org-switch
ENOENT: no such file or directory, open '<path>'.apex file path is wrong or relative to the wrong cwdConfirm absolute path; re-run
compileProblem non-empty in JSONApex compile errorSurface compileProblem, line, column; show that line; suggest a fix
success: false with exceptionMessageRuntime exception inside the anonymous blockSurface exception type + message + stack; show governor counts if present
logs field is empty even on successNo active TraceFlag for running userTell developer to run sf apex tail log --target-org <alias> in another terminal, then re-run
status !== 0 with no resultCLI / network / auth failure before executionSurface raw stderr; do not retry blindly
Unrecognized flag errorSpec drift with the installed CLIRe-check sf apex run --help; do not invent flags

Rules

  • Always pass --json.
  • Always resolve <alias> from configuration or the developer; never hardcode.
  • Never use --apex-code-style inline flags — they are not supported by the current CLI and are escape-hostile. Always go through --file.
  • Always echo a pasted snippet back to the developer for confirmation before executing.
  • For verification-style scripts, default to wrapping in Database.setSavepoint() + Database.rollback().
  • For prod orgs, surface a heads-up but do not auto-block — the developer is in charge.
  • Do not auto-delete temp files under .sfdx/tmp/.
  • This skill executes anonymous Apex; it does not author, deploy, or test .cls/.trigger files. For those, hand off to platform-apex-generate, the deploy skills, or platform-apex-test-generate.
  • For deep log analysis, hand off to platform-apex-logs-debug.

來源與署名

來源:forcedotcom/sf-skills位於plugins/builder/salesforce-development/skills/platform-apex-anonymous-run提交3c15867

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架

更多來自 forcedotcom/sf-skills 的技能

Service Itsm Teams Itservice Configure

forcedotcom

Configure the "Set Up Salesforce IT Service" checklist for Microsoft Teams Employee Service (ITSM) — the employee side, covering app enablement, marketplace install guidance, user access assignment, and Digital Experience Site selection. Use this for: 'turn on Salesforce IT Service', 'set up IT Service on Teams', 'assign Teams for Employee permission set', 'give employees access to Teams for Employee Service', 'manage user access for Teams ITSM', 'grant users the permission sets needed for Teams Employee Service', 'select a digital experience site for Teams', 'install Salesforce IT Service app on Teams', or any request to complete the IT Service half of the Teams ITSM Go page checklist (including the Manage User Access step). DO NOT TRIGGER for the base Teams Salesforce Go page toggle or Azure/Entra app setup (service-itsm-teams-configure) or for the IT Desk/fulfiller half of the checklist (service-itsm-teams-itdesk-configure).

待分類1K昨天更新

Service Itsm Teams Coordinate

forcedotcom

End-to-end autopilot orchestrator for setting up Microsoft Teams integration in Salesforce Service Cloud ITSM — runs the whole flow (enable the Teams for Employee Service Go feature, register the Microsoft Entra app, populate Named Credentials, configure the IT Desk and IT Service checklists, turn on Swarming, and optionally embed the Agentforce agent) in one continuous pass, stopping only at the points a human must act. Use when the user asks to set up Microsoft Teams for ITSM end to end, 'set up teams for it service', 'do the whole teams itsm setup', 'configure microsoft teams for employee service', or wants a guided Teams ITSM walkthrough. Delegates each stage to a specialized child skill while driving the sequence itself. DO NOT TRIGGER when the user asks to enable Teams alone, configure just the IT Desk or IT Service checklist alone, or enable Swarming alone — delegate directly to the specific child skill in those cases.

待分類1K昨天更新

Service Itsm Teams Itdesk Configure

forcedotcom

Configure the "Set Up Salesforce IT Desk" checklist for Microsoft Teams Employee Service (ITSM) — the fulfiller/agent side, covering app enablement, marketplace install guidance, user access assignment, and Swarming collaboration-tool setup. Use this for: 'turn on Salesforce IT Desk', 'set up IT Desk on Teams', 'assign Teams for IT Desk permission set', 'set Teams as collaboration tool for swarming', 'install Salesforce IT Desk app on Teams', or any request to complete the IT Desk half of the Teams ITSM Go page checklist. DO NOT TRIGGER for the base Teams Salesforce Go page toggle or Azure/Entra app setup (service-itsm-teams-configure) or for the IT Service/employee half of the checklist (service-itsm-teams-itservice-configure).

待分類1K昨天更新

Service Itsm Teams Debug

forcedotcom

透過對 Salesforce 組織執行通過/失敗設定檢查清單,診斷 Microsoft Teams 員工服務(ITSM)設定失敗問題。

DevOps & Cloud1K昨天更新

Service Itsm Teams Employee Agent Configure

forcedotcom

Configure the embedded Agentforce Employee Agent so it replies inside the Microsoft Teams ITSM custom client ('Salesforce Employee Assist' / 'Ask AI Agent'). Use this for: 'set up employee agent in Teams', 'embed Agentforce agent in Teams', 'make the IT Service Employee Agent reply in Teams', 'Teams Ask AI Agent not responding', 'agent joins then leaves without replying', 'configure MIAW deployment for Teams employee agent', 'Teams embedded messaging agent setup'. Builds the whole stack headlessly (zero Setup-UI clicks): the Web messaging channel with User Verification ON, the Enhanced Chat User Verification Key Set (JWKS_URL) it requires, the Teams_AgentForce custom-client deployment, the routing flow to the agent, and the Agent Access permission set that lets the portal user reach the agent. DO NOT TRIGGER for enabling the Teams feature Salesforce Go page toggle (service-itsm-teams-configure) or for configuring notification preferences.

待分類1K昨天更新

Service Itsm Swarming Configure

forcedotcom

透過 Connect API 呼叫啟用 Salesforce Swarming ITSM 功能,並將協作工具設為 Teams。

DevOps & Cloud1K昨天更新