Skip to main content

vulkro-sf org health-check

Pro

Every live-org command (vulkro-sf org ...) is part of Pro: Live-org audit (sf-live-org), permissions, session, MFA, sharing, packages and trust, read from the org itself. On Free it stops before doing any work, prints what it needs and where to get it, and exits 1. See Pricing.

Surfaces the Salesforce-computed Security Health Check score (SF-HEALTH-CHECK-001).

This is the one org subcommand where the analysis is Salesforce's own, not Vulkro's. The command reads the platform's Health Check result and turns each risk category into a finding, so the score sits alongside the rest of the live-org audit in one place and in one output format.

Synopsis

vulkro-sf org health-check --target-org <alias> [flags]

Flags

FlagTypeDefaultDescription
--target-org, -o <alias>string(required)Target org alias or username, as known to sf org login.
--format <fmt>enumtableOutput format.
--verbose, -vflagoffBump stderr log verbosity. -v enables debug-level tracing for the vulkro + vulkro_sf targets; -vv enables trace. Honoured only when RUST_LOG is unset (an explicit RUST_LOG always wins).

What gets read

The JSON body of the org's connect/security-health-check REST resource: the overallScore and the riskCategories array.

What gets reported

One SF-HEALTH-CHECK-001 finding per risk category with a non-zero risk count, carrying the category name, its risk count, and the org's overall score. Signal health-check-risk-category.

Severity is derived from the Salesforce-computed overall score, not per category:

Overall scoreSeverity
Below 60High
60 to 80Medium
Above 80Low

Remediation points at Setup -> Security Health Check, where the failed items in each category and the recommended baseline values are listed.

Examples

vulkro-sf org health-check --target-org my-prod

vulkro-sf org health-check -o my-prod --format json > health-check.json

Exit codes

  • 0 - no findings.
  • 1 - posture findings reported.
  • 2 - error.

These follow the org command-family contract printed by vulkro-sf org --help.

Scope and honesty

The org is read locally through your own authenticated sf CLI login; nothing is sent anywhere.

The score and the risk categories are computed by Salesforce against Salesforce's baseline. Vulkro reports them, it does not recompute them, and it does not second-guess them. A high score is Salesforce's assessment of settings drift against a baseline: it is not a certification that the org is secure, and it says nothing about the Apex, LWC, sharing, or permission risks the other org subcommands cover.

Where to go next