跳到主要内容
知仓学习社ZHICANG

service-omni-command-center-analyze

Use to analyze whether an org should use Command Center for Service V2 or classic Omni Supervisor and recommend the next action without making chang…

读凭据执行命令严重 0 · 高危 3forcedotcom/sf-skills

它会碰到什么

扫了多少5 个文本文件,28 KB
它会碰到什么读凭据执行命令
命中总数3 处
命中统计严重 0 · 高 3 · 中 0 · 低 0
逐条看命中(3 条严重或高危)
  • scripts/tests/_bootstrap.py:88cred-envread
    env["PATH"] = os.pathsep.join(kept)
  • scripts/tests/_bootstrap.py:90cred-envread
    env["PATH"] = path_prefix + os.pathsep + env.get("PATH", "")
  • scripts/tests/_bootstrap.py:93exec-spawn
    proc = subprocess.run(

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

service-omni-command-center-analyze

Decide, without changing anything, which supervisor experience an org should use and what to do next. Command Center for Service V2 is gated on three independent dimensions — org capability (release gater), the CommandCenterForServiceV2 org preference (whose ON-flip seeds the CommandCenterForServiceV2_L FlexiPage and registers the V2 tab), and the per-supervisor CommandCenterForServiceUser permission. A single boolean cannot express that, so this skill returns an explicit state plus the recommended follow-up skill (e.g. service-omni-supervisor-config-deploy for the classic path). It is the entry point of the Command Center flow — service-omni-channel-setup-coordinate runs it first — and is safe to run on any org, including production, because it only reads.

Inputs

bash scripts/analyze.sh <org-alias> [supervisor_username_or_id]
  • org-alias (required).
  • supervisor_username_or_id (optional). A Username (…@…) or 15/18-char User Id (005…). When given, the per-user CommandCenterForServiceUser permission is evaluated; when omitted, the permission dimension is reported as not-checked and readiness is org-level only.

Preconditions and safety

  • Target org authenticated via sf CLI, Service Cloud license, sf CLI ≥ 2.139.6.
  • Read-only — no safe_to_write guard is needed; the skill issues only SOQL/Tooling queries.

Run

analyze.sh gathers observable signals and maps them to a state:

| Signal | Source | Meaning |

|---|---|---|

| V2 capability | SELECT Id FROM PermissionSet WHERE PermissionsCommandCenterForServiceUser = true probe | If the user-permission column does not exist on the org schema, V2 is not available. |

| Seeded FlexiPage | Tooling: FlexiPage where DeveloperName='CommandCenterForServiceV2_L' | Present ⇒ the org preference was enabled and the page was seeded. |

| V2 tab | TabDefinition (best-effort) | Cross-checks the seed; a seed/tab mismatch indicates a partial provision. |

| Supervisor permission | PermissionSetAssignment joined on PermissionSet.PermissionsCommandCenterForServiceUser | Whether the named supervisor can use V2. |

| Legacy config | Tooling: OmniSupervisorConfig count | Informational for the classic path. |

Behavior

States and recommended next action:

| State | Meaning | Recommended skill |

|---|---|---|

| v2_ready | Capability + seed present (and supervisor has permission, if checked) | verify only (coordinator proceeds to V2 verification) |

| v2_permission_missing | V2 enabled but the named supervisor lacks CommandCenterForServiceUser | Manual — assign CommandCenterForServiceUser (headless-capable via PermissionSet; packaging pending) |

| v2_seed_incomplete | Capability present but the FlexiPage/tab provisioning is inconsistent | Manual — re-check in Setup → Omni-Channel → Supervisor Settings (no supported public write API) |

| v2_available_not_enabled | Org supports V2 but the preference is off | Manual — enable in Setup → Omni-Channel → Supervisor Settings (no supported Metadata/Tooling write API) |

| legacy_selected | V2 capability absent | service-omni-supervisor-config-deploy |

| ambiguous | A required signal could not be read through a supported API | none — blocks, do not guess |

ambiguous is the only state that exits non-zero: the review's rule is to block rather than infer when state cannot be proven read-only. All other states exit 0 with status:"detected".

Output contract

A single JSON object: status (detected | blocked), state (one of the six above), recommended_action, recommended_skill, signals (v2_capability, seed_flexipage_present, v2_tab_present, supervisor{identifier,checked,has_command_center_permission}, legacy_omnisupervisorconfig_count), manual_actions, blocking_issue.

Limitations

  • The CommandCenterForServiceV2 org preference has no supported public read; its state is inferred from the seeded FlexiPage (the platform seeds on the ON-flip). This is called out in signals and is why a bare capability-without-seed reads as v2_available_not_enabled.
  • The release gater cannot be read directly; capability is inferred from the presence of the user-permission column on the org schema.
  • Tab detection is best-effort; when the tab query cannot run, v2_tab_present is "unknown" and state is derived from the remaining signals.
  • Read-only: it never enables V2, seeds pages, assigns permissions, or deploys config.

References

| File | When to read |

|---|---|

| references/api-notes.md | The three-dimensional V2 gate, why each signal is a proxy, and the exact queries used |

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。