Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .claude-plugin/marketplace.json
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@
{ "name": "agent-portability-skills", "source": "./plugins/agent-portability-skills", "description": "Cross-host agent-skill and plugin portability workflows.", "category": "developer-tools", "tags": ["skills", "portability"], "strict": false },
{ "name": "android-dev-skills", "source": "./plugins/android-dev-skills", "description": "Android, Kotlin, Java, Gradle, testing, and release workflows.", "category": "developer-tools", "tags": ["android", "skills"], "strict": false },
{ "name": "apple-creator-studio-skills", "source": "./plugins/apple-creator-studio-skills", "description": "Apple Creator Studio workflows for production and delivery.", "category": "productivity", "tags": ["apple", "creative"], "strict": false },
{ "name": "apple-dev-skills", "source": "./plugins/apple-dev-skills", "description": "Apple, SwiftPM, Xcode, and macOS or Linux virtualization workflows.", "category": "developer-tools", "tags": ["apple", "swift", "swiftpm", "xcode", "virtualization"], "mcpServers": "./.mcp.json", "strict": false },
{ "name": "apple-dev-skills", "source": "./plugins/apple-dev-skills", "description": "Apple, SwiftPM, Xcode, macOS privacy, file access, entitlement, and virtualization workflows.", "category": "developer-tools", "tags": ["apple", "swift", "swiftpm", "xcode", "macos", "privacy", "entitlements", "virtualization"], "mcpServers": "./.mcp.json", "strict": false },
{ "name": "cardhop-app", "source": "./plugins/cardhop-app", "description": "Cardhop contact workflows with a Claude Code local MCP server.", "category": "productivity", "tags": ["contacts", "macos", "local-mcp"], "mcpServers": "./claude.mcp.json", "strict": false },
{ "name": "cloud-deployment-skills", "source": "./plugins/cloud-deployment-skills", "description": "Cloud deployment routing and provider integration workflows.", "category": "developer-tools", "tags": ["cloud", "deployment"], "strict": false },
{ "name": "cloud-inference-skills", "source": "./plugins/cloud-inference-skills", "description": "Cloud AI inference, training, conversion, and GPU workflows.", "category": "developer-tools", "tags": ["ai", "cloud", "mcp"], "mcpServers": "./.mcp.json", "strict": false },
Expand All @@ -21,7 +21,7 @@
{ "name": "network-protocol-skills", "source": "./plugins/network-protocol-skills", "description": "Networking, transport, QUIC, HTTP/3, and WebRTC workflows.", "category": "developer-tools", "tags": ["networking", "protocols"], "strict": false },
{ "name": "productivity-skills", "source": "./plugins/productivity-skills", "description": "Maintainer, documentation, job-search, and automation-design workflows.", "category": "productivity", "tags": ["maintenance", "automation", "mcp"], "mcpServers": "./.mcp.json", "strict": false },
{ "name": "python-skills", "source": "./plugins/python-skills", "description": "Python, uv, FastAPI, FastMCP, testing, and packaging workflows.", "category": "developer-tools", "tags": ["python", "uv"], "strict": false },
{ "name": "reverse-engineering-skills", "source": "./plugins/reverse-engineering-skills", "description": "Artifact triage, binary analysis, and reproducible evidence workflows.", "category": "developer-tools", "tags": ["reverse-engineering", "security"], "strict": false },
{ "name": "reverse-engineering-skills", "source": "./plugins/reverse-engineering-skills", "description": "Artifact triage, binary analysis, exact-build macOS control research, and reproducible evidence workflows.", "category": "developer-tools", "tags": ["reverse-engineering", "security", "macos", "forensics"], "strict": false },
{ "name": "rust-skills", "source": "./plugins/rust-skills", "description": "Rust, Cargo, crate, test, CI, and package workflows.", "category": "developer-tools", "tags": ["rust", "cargo"], "strict": false },
{ "name": "server-side-jvm", "source": "./plugins/server-side-jvm", "description": "Java, Scala, JVM service, build, and testing workflows.", "category": "developer-tools", "tags": ["java", "scala", "jvm"], "strict": false },
{ "name": "server-side-swift", "source": "./plugins/server-side-swift", "description": "Vapor, Hummingbird, SwiftNIO, Docker, and Apple container workflows.", "category": "developer-tools", "tags": ["swift", "server", "containers"], "strict": false },
Expand Down
35 changes: 35 additions & 0 deletions ROADMAP.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,7 @@
- [Milestone 28: Swift language tooling expansion](#milestone-28-swift-language-tooling-expansion)
- [Milestone 29: Model Lab skills plugin](#milestone-29-model-lab-skills-plugin)
- [Milestone 30: macOS virtualization and container skills expansion](#milestone-30-macos-virtualization-and-container-skills-expansion)
- [Milestone 31: macOS platform security skills expansion](#milestone-31-macos-platform-security-skills-expansion)
- [Small Tickets](#small-tickets)
- [Backlog Candidates](#backlog-candidates)
- [History](#history)
Expand Down Expand Up @@ -75,6 +76,7 @@
- Milestone 28: Swift language tooling expansion - In Progress
- Milestone 29: Model Lab skills plugin - Planned
- Milestone 30: macOS virtualization and container skills expansion - Completed
- Milestone 31: macOS platform security skills expansion - Completed

## Milestone 5: SwiftASB skills plugin

Expand Down Expand Up @@ -1033,6 +1035,39 @@ Completed

Completed Milestone 30 by shipping four Apple Dev virtualization workflows, a disposable Cybersecurity lab-preparation workflow, Apple `container` 1.x and `container machine` guidance, guest-versus-host evidence rules, Hermes exports, Claude and Cowork compatibility metadata, architecture inventory updates, and ten scenario-level forward tests. The rebased `9.19.0` release candidate preserves the concurrent Model Lab inventory and passed 268 Apple Dev tests, 126 Socket tests with one intentional skip, Apple and Cybersecurity child validators, Socket marketplace validation, Hermes parity, Claude/Cowork validation, and the architecture consistency check.

## Milestone 31: macOS platform security skills expansion

### Status

Completed

### Scope

- [x] Record the source baseline, ownership, control-layer model, evidence record, skill contracts, fixtures, compatibility, validation, and implementation slices in [`docs/maintainers/macos-platform-security-skills-plan.md`](./docs/maintainers/macos-platform-security-skills-plan.md).
- [x] Add three Apple Dev workflows for privacy permissions, sandboxed file access, and entitlement diagnosis without creating a duplicate macOS security plugin.
- [x] Add one Reverse Engineering workflow for exact-build public/private macOS security-control research and technical notes.
- [x] Align existing Cybersecurity macOS workflows around explicit developer, research, threat-assessment, and isolation handoffs without moving defensive ownership.
- [x] Keep the first implementation instruction-only: no TCC database mutation, permission grant service, privileged helper, daemon, endpoint agent, MCP server, protection bypass, or live-host prompt automation.

### Planned Slices

- [x] Slice 1: ship `apple-dev-skills:macos-privacy-permissions-workflow` with responsible-code attribution, public API, prompt/settings, reset-only, PPPC, and disposable-fixture contracts.
- [x] Slice 2: ship `apple-dev-skills:macos-sandbox-file-access-workflow` and `apple-dev-skills:diagnose-apple-entitlements`, then align provisioning, distribution, extension, File Provider, and Xcode handoffs.
- [x] Slice 3: ship `reverse-engineering-skills:research-macos-security-control`, connect exact-build research and technical notes to existing artifact/signing/dynamic-analysis workflows, and align Cybersecurity handoffs.
- [x] Slice 4: forward-test the complete scenario matrix, remediate trigger and handoff gaps, update discovery metadata and user-facing inventory, export portable skills through Hermes, record Claude/Cowork compatibility, and run full affected validation.
- [x] Reconsider a standalone `macos-security-skills` plugin or shared read-only diagnostic collector only after repeated implementation use satisfies the explicit gate in the maintainer plan; retain the focused existing owners for this release.

### Exit Criteria

- [x] Agents identify the responsible executable and controlling security layer before suggesting a permission, entitlement, signing, distribution, malware, or system-policy change.
- [x] Public application guidance never treats private TCC symbols, direct database access, `tccutil reset`, an entitlement, or administrator privileges as a supported permission grant.
- [x] File-access guidance preserves the complete security-scoped bookmark lifecycle and distinguishes App Sandbox, TCC, POSIX/ACL, Data Vault, and SIP failures.
- [x] Entitlement guidance compares requested behavior, tracked source, account/profile authorization, final signed code, and runtime authorization for every affected target.
- [x] Private-control research records exact builds and clearly separates public contract, private implementation evidence, runtime observation, inference, and transformed artifacts.
- [x] Apple Dev, Reverse Engineering, Cybersecurity, Socket, Hermes, and Claude/Cowork discovery and validation surfaces agree on the shipped owner boundaries.

Completed Milestone 31 by shipping four focused, instruction-only macOS platform-security workflows across Apple Dev and Reverse Engineering Skills, aligning defensive Cybersecurity handoffs, preserving visible prompt and protection-state approval gates, exporting the portable skill set through Hermes, and recording Claude Code/Cowork compatibility without introducing a permission manager, privileged service, or duplicate plugin.

## Small Tickets

- [ ] Record issue-sized fixes, TODO/FIXME imports, and cleanup work that is too small or too unplanned for a milestone.
Expand Down
10 changes: 10 additions & 0 deletions docs/architecture/ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -82,6 +82,7 @@ See [SLICES.md](./SLICES.md) for provable end-to-end code paths.
- `skill:apple-dev-skills/coreaudio-modernization-repair-workflow` (codex-skill) at `plugins/apple-dev-skills/skills/coreaudio-modernization-repair-workflow/SKILL.md` depends on: no declared dependencies.
- `skill:apple-dev-skills/coremedia-timing-samplebuffer-workflow` (codex-skill) at `plugins/apple-dev-skills/skills/coremedia-timing-samplebuffer-workflow/SKILL.md` depends on: no declared dependencies.
- `skill:apple-dev-skills/devicecheck-app-attest-workflow` (codex-skill) at `plugins/apple-dev-skills/skills/devicecheck-app-attest-workflow/SKILL.md` depends on: no declared dependencies.
- `skill:apple-dev-skills/diagnose-apple-entitlements` (codex-skill) at `plugins/apple-dev-skills/skills/diagnose-apple-entitlements/SKILL.md` depends on: no declared dependencies.
- `skill:apple-dev-skills/explore-apple-swift-docs` (codex-skill) at `plugins/apple-dev-skills/skills/explore-apple-swift-docs/SKILL.md` depends on: no declared dependencies.
- `skill:apple-dev-skills/feedback-assistant-workflow` (codex-skill) at `plugins/apple-dev-skills/skills/feedback-assistant-workflow/SKILL.md` depends on: no declared dependencies.
- `skill:apple-dev-skills/file-provider-and-finder-sync-workflow` (codex-skill) at `plugins/apple-dev-skills/skills/file-provider-and-finder-sync-workflow/SKILL.md` depends on: no declared dependencies.
Expand All @@ -91,11 +92,14 @@ See [SLICES.md](./SLICES.md) for provable end-to-end code paths.
- `skill:apple-dev-skills/linux-development-vm-workflow` (codex-skill) at `plugins/apple-dev-skills/skills/linux-development-vm-workflow/SKILL.md` depends on: no declared dependencies.
- `skill:apple-dev-skills/macos-development-vm-workflow` (codex-skill) at `plugins/apple-dev-skills/skills/macos-development-vm-workflow/SKILL.md` depends on: no declared dependencies.
- `skill:apple-dev-skills/macos-distribution-workflow` (codex-skill) at `plugins/apple-dev-skills/skills/macos-distribution-workflow/SKILL.md` depends on: no declared dependencies.
- `skill:apple-dev-skills/macos-privacy-permissions-workflow` (codex-skill) at `plugins/apple-dev-skills/skills/macos-privacy-permissions-workflow/SKILL.md` depends on: no declared dependencies.
- `skill:apple-dev-skills/macos-sandbox-file-access-workflow` (codex-skill) at `plugins/apple-dev-skills/skills/macos-sandbox-file-access-workflow/SKILL.md` depends on: no declared dependencies.
- `skill:apple-dev-skills/macos-window-management-workflow` (codex-skill) at `plugins/apple-dev-skills/skills/macos-window-management-workflow/SKILL.md` depends on: no declared dependencies.
- `skill:apple-dev-skills/mailkit-workflow` (codex-skill) at `plugins/apple-dev-skills/skills/mailkit-workflow/SKILL.md` depends on: no declared dependencies.
- `skill:apple-dev-skills/migrate-xcode-project-to-xcodegen` (codex-skill) at `plugins/apple-dev-skills/skills/migrate-xcode-project-to-xcodegen/SKILL.md` depends on: no declared dependencies.
- `skill:apple-dev-skills/photos-library-editing-workflow` (codex-skill) at `plugins/apple-dev-skills/skills/photos-library-editing-workflow/SKILL.md` depends on: no declared dependencies.
- `skill:apple-dev-skills/safari-extension-control-workflow` (codex-skill) at `plugins/apple-dev-skills/skills/safari-extension-control-workflow/SKILL.md` depends on: no declared dependencies.
- `skill:apple-dev-skills/safari-mcp-workflow` (codex-skill) at `plugins/apple-dev-skills/skills/safari-mcp-workflow/SKILL.md` depends on: no declared dependencies.
- `skill:apple-dev-skills/sf-symbols-workflow` (codex-skill) at `plugins/apple-dev-skills/skills/sf-symbols-workflow/SKILL.md` depends on: no declared dependencies.
- `skill:apple-dev-skills/structure-swift-sources` (codex-skill) at `plugins/apple-dev-skills/skills/structure-swift-sources/SKILL.md` depends on: no declared dependencies.
- `skill:apple-dev-skills/swift-openapi-client-workflow` (codex-skill) at `plugins/apple-dev-skills/skills/swift-openapi-client-workflow/SKILL.md` depends on: no declared dependencies.
Expand Down Expand Up @@ -265,6 +269,7 @@ See [SLICES.md](./SLICES.md) for provable end-to-end code paths.
- `skill:reverse-engineering-skills/recover-apple-runtime-metadata` (codex-skill) at `plugins/reverse-engineering-skills/skills/recover-apple-runtime-metadata/SKILL.md` depends on: no declared dependencies.
- `skill:reverse-engineering-skills/report-apple-security-research` (codex-skill) at `plugins/reverse-engineering-skills/skills/report-apple-security-research/SKILL.md` depends on: no declared dependencies.
- `skill:reverse-engineering-skills/research-apple-kernel-boot-and-firmware` (codex-skill) at `plugins/reverse-engineering-skills/skills/research-apple-kernel-boot-and-firmware/SKILL.md` depends on: no declared dependencies.
- `skill:reverse-engineering-skills/research-macos-security-control` (codex-skill) at `plugins/reverse-engineering-skills/skills/research-macos-security-control/SKILL.md` depends on: no declared dependencies.
- `skill:reverse-engineering-skills/review-decompiler-output` (codex-skill) at `plugins/reverse-engineering-skills/skills/review-decompiler-output/SKILL.md` depends on: no declared dependencies.
- `skill:reverse-engineering-skills/script-hopper-analysis` (codex-skill) at `plugins/reverse-engineering-skills/skills/script-hopper-analysis/SKILL.md` depends on: no declared dependencies.
- `skill:reverse-engineering-skills/select-analysis-path` (codex-skill) at `plugins/reverse-engineering-skills/skills/select-analysis-path/SKILL.md` depends on: no declared dependencies.
Expand Down Expand Up @@ -378,6 +383,7 @@ The structured visual model lives in [architecture.json](./architecture.json). I
- `skill-manifest` evidence from `plugins/apple-dev-skills/skills/coreaudio-modernization-repair-workflow/SKILL.md`.
- `skill-manifest` evidence from `plugins/apple-dev-skills/skills/coremedia-timing-samplebuffer-workflow/SKILL.md`.
- `skill-manifest` evidence from `plugins/apple-dev-skills/skills/devicecheck-app-attest-workflow/SKILL.md`.
- `skill-manifest` evidence from `plugins/apple-dev-skills/skills/diagnose-apple-entitlements/SKILL.md`.
- `skill-manifest` evidence from `plugins/apple-dev-skills/skills/explore-apple-swift-docs/SKILL.md`.
- `skill-manifest` evidence from `plugins/apple-dev-skills/skills/feedback-assistant-workflow/SKILL.md`.
- `skill-manifest` evidence from `plugins/apple-dev-skills/skills/file-provider-and-finder-sync-workflow/SKILL.md`.
Expand All @@ -387,11 +393,14 @@ The structured visual model lives in [architecture.json](./architecture.json). I
- `skill-manifest` evidence from `plugins/apple-dev-skills/skills/linux-development-vm-workflow/SKILL.md`.
- `skill-manifest` evidence from `plugins/apple-dev-skills/skills/macos-development-vm-workflow/SKILL.md`.
- `skill-manifest` evidence from `plugins/apple-dev-skills/skills/macos-distribution-workflow/SKILL.md`.
- `skill-manifest` evidence from `plugins/apple-dev-skills/skills/macos-privacy-permissions-workflow/SKILL.md`.
- `skill-manifest` evidence from `plugins/apple-dev-skills/skills/macos-sandbox-file-access-workflow/SKILL.md`.
- `skill-manifest` evidence from `plugins/apple-dev-skills/skills/macos-window-management-workflow/SKILL.md`.
- `skill-manifest` evidence from `plugins/apple-dev-skills/skills/mailkit-workflow/SKILL.md`.
- `skill-manifest` evidence from `plugins/apple-dev-skills/skills/migrate-xcode-project-to-xcodegen/SKILL.md`.
- `skill-manifest` evidence from `plugins/apple-dev-skills/skills/photos-library-editing-workflow/SKILL.md`.
- `skill-manifest` evidence from `plugins/apple-dev-skills/skills/safari-extension-control-workflow/SKILL.md`.
- `skill-manifest` evidence from `plugins/apple-dev-skills/skills/safari-mcp-workflow/SKILL.md`.
- `skill-manifest` evidence from `plugins/apple-dev-skills/skills/sf-symbols-workflow/SKILL.md`.
- `skill-manifest` evidence from `plugins/apple-dev-skills/skills/structure-swift-sources/SKILL.md`.
- `skill-manifest` evidence from `plugins/apple-dev-skills/skills/swift-openapi-client-workflow/SKILL.md`.
Expand Down Expand Up @@ -573,6 +582,7 @@ The structured visual model lives in [architecture.json](./architecture.json). I
- `skill-manifest` evidence from `plugins/reverse-engineering-skills/skills/recover-apple-runtime-metadata/SKILL.md`.
- `skill-manifest` evidence from `plugins/reverse-engineering-skills/skills/report-apple-security-research/SKILL.md`.
- `skill-manifest` evidence from `plugins/reverse-engineering-skills/skills/research-apple-kernel-boot-and-firmware/SKILL.md`.
- `skill-manifest` evidence from `plugins/reverse-engineering-skills/skills/research-macos-security-control/SKILL.md`.
- `skill-manifest` evidence from `plugins/reverse-engineering-skills/skills/review-decompiler-output/SKILL.md`.
- `skill-manifest` evidence from `plugins/reverse-engineering-skills/skills/script-hopper-analysis/SKILL.md`.
- `skill-manifest` evidence from `plugins/reverse-engineering-skills/skills/select-analysis-path/SKILL.md`.
Expand Down
Loading