Agent skill

Audit Xcode Security Settings

by CamilleScholtz in CamilleScholtz/swmpc

Audit and enable security-oriented Xcode build settings, compiler warnings, static analysis, and Enhanced Security features.

EUPL-1.2Auto-check passedMobile

Install Audit Xcode Security Settings

skills CLI
$ npx skills add CamilleScholtz/swmpc --skill audit-xcode-security-settings -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install CamilleScholtz/swmpc audit-xcode-security-settings --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/CamilleScholtz/swmpc.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/audit-xcode-security-settings .claude/skills/audit-xcode-security-settings && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-xcode-security-settings
GitHub stars
239
Token cost
~12k tokens
SKILL.md length
6,079 words
Files
17 (incl. scripts, references)
Skills in repo
27
Repo updated
First seen
Licence
EUPL-1.2

At a glance

Audit and enable security-oriented Xcode build settings, compiler warnings, static analysis, and Enhanced Security features.

  • Works in 2 steps: Briefing → Discovery
  • Tasks that involve iOS development
  • SKILL.md covers Tool Preferences, Bundled Reference Documents, Workflow and Phase 1: Briefing, plus 3 more sections
  • Runs Python scripts from its folder; calls xcodebuild and python3; reaches clang.llvm.org

What it does

Audit Xcode Security Settings is an agent skill from CamilleScholtz/swmpc. Audit and enable security-oriented Xcode build settings, compiler warnings, static analysis, and Enhanced Security features.

Its SKILL.md is about 12k tokens, which your agent loads only when the skill is triggered. The skill folder holds 18 other files, including scripts and reference files (for example `references/additional-settings.md`, `references/adoption-strategy.md` and `references/cpp-hardening.md`).

It sits in Mobile, covering iOS development. It works with Xcode and Model Context Protocol. The repository describes itself as: An MPD client for macOS & iOS.

When your agent uses it

  • Tasks that involve iOS development

Example prompts

  • “/audit-xcode-security-settings”

Requirements

  • Python 3

Workflow steps

2 steps, taken from the step headings in SKILL.md.

  1. Briefing
  2. Discovery

What it can do on your machine

Read from SKILL.md and the folder at commit 51fa7cb. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • xcodebuild
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • clang.llvm.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Xcode Security Settings loads about 12k tokens when it runs, and up to ~29k if it reads all its reference files. Until then it costs about 39 tokens; SKILL.md has 6,079 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~39
When it runs · the whole SKILL.md, loaded when a task matches
~12k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~29k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

Its licence (EUPL-1.2) doesn't allow us to republish the file, so here is its outline and opening line. It has 6,079 words (~12,409 tokens).

“Assess an Xcode project's security posture and progressively enable security build settings and entitlements — from broadly applicable warnings through Enhanced Security hardening.”

— opening of SKILL.md by CamilleScholtz, EUPL-1.2
name
audit-xcode-security-settings

Read the full SKILL.md on GitHub

Files

SKILL.md and 16 other files (scripts, references) in .agents/skills/audit-xcode-security-settings of CamilleScholtz/swmpc.

  • SKILL.md
  • references/additional-settings.md
  • references/adoption-strategy.md
  • references/cpp-hardening.md
  • references/decision-document.md
  • references/enhanced-security.md
  • references/hardware-memory-tagging.md
  • references/pointer-authentication.md
  • references/reading-build-settings.md
  • references/readonly-platform-memory.md
  • references/runtime-restrictions.md
  • references/security-compiler-warnings.md
  • references/security-settings-reference.md
  • references/stack-zero-init.md
  • references/typed-allocators.md
  • references/universal-binaries-for-libraries.md
  • scripts/filter_build_settings.py

Open the folder on GitHubat commit 51fa7cb

Compare with similar skills

Audit Xcode Security Settings next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Xcode Security Settings compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Xcode Security Settings this skillCamilleScholtz/swmpc239—~12kAutomated safety check: PassEUPL-1.2
Update Swiftui APIsAvdLee/SwiftUI-Agent-Skill3.7k—~1.2kAutomated safety check: PassMIT
iOS Simulator Skillconorluddy/ios-simulator-skill1.3k—~5.7kAutomated safety check: PassMIT
Inspector MCPipedro/Inspector170—~3.4kAutomated safety check: PassMIT
Xcode Buildpzep1/xcode-build-skill138—~1.5kAutomated safety check: NotesMIT
Dt Setup iOSDynatrace/dynatrace-for-ai161—~3.3kAutomated safety check: PassApache-2.0

Similar skills

  • Update Swiftui APIs

    AvdLee/SwiftUI-Agent-Skill

    Scan Apple's SwiftUI documentation for deprecated APIs and update the SwiftUI Expert Skill with modern replacements.

    3.7k GitHub stars~1.2k tokensUpdated 2 days ago
    MobileAuto-check passed
  • iOS Simulator Skill

    conorluddy/ios-simulator-skill

    29 production-ready scripts for iOS app testing, building, and automation.

    1.3k GitHub stars~5.7k tokensUpdated 2 days ago
    MobileAuto-check passed
  • Inspector MCP

    ipedro/Inspector

    A skill your agent uses when an agent needs to inspect a live iOS app through the Inspector MCP bridge, register or troubleshoot InspectorMCPServer for a consumer Xcode project, or query, resolve…

    170 GitHub stars~3.4k tokensUpdated 5 mo ago
    MobileAuto-check passed
  • Xcode Build

    pzep1/xcode-build-skill

    Build and run iOS/macOS apps using xcodebuild and xcrun simctl directly.

    138 GitHub stars~1.5k tokensUpdated 8 mo ago
    MobileAuto-check: notes
  • Dt Setup iOS

    Dynatrace/dynatrace-for-ai

    Set up the Dynatrace iOS SDK (OneAgent) in an iOS project using Swift Package Manager.

    161 GitHub stars~3.3k tokensUpdated 7 days ago
    MobileAuto-check passed
  • Inspector MCP Consumer

    ipedro/Inspector

    A skill your agent uses when an agent needs to patch a consumer iOS app so it exposes the Inspector MCP bridge, add or verify the app-side Inspector startup configuration, or choose the correct…

    170 GitHub stars~926 tokensUpdated 5 mo ago
    MobileAuto-check passed

More from CamilleScholtz/swmpc

All 27 skills in this repo
  • Asc Localize Metadata

    CamilleScholtz/swmpc

    Automatically translate and sync App Store metadata (description, keywords, what's new, subtitle) to multiple languages using LLM translation and asc CLI.

    239 GitHub starsUsed in 5 repos~2.8k tokens
    Auto-check passed
  • Asc Screenshot Resize

    CamilleScholtz/swmpc

    Resize and validate App Store screenshots with current asc screenshot-size data and macOS sips.

    239 GitHub starsUsed in 4 repos~927 tokens
    Auto-check passed
  • Asc Shots Pipeline

    CamilleScholtz/swmpc

    Orchestrate iOS screenshot automation with xcodebuild/simctl for build-run, AXe for UI actions, JSON settings and plan files, Koubou-based framing (asc screenshots frame), and screenshot upload (asc…

    239 GitHub starsUsed in 4 repos~2.8k tokens
    Auto-check passed
  • Asc Signing Setup

    CamilleScholtz/swmpc

    Set up bundle IDs, capabilities, signing certificates, provisioning profiles, and encrypted signing sync with the asc cli.

    239 GitHub starsUsed in 4 repos~1.1k tokens
    Auto-check passed
  • Asc Metadata Sync

    CamilleScholtz/swmpc

    Sync, validate, and apply App Store metadata with the current asc canonical metadata workflow.

    239 GitHub starsUsed in 3 repos~1.5k tokens
    Auto-check passed
  • Asc Aso Audit

    CamilleScholtz/swmpc

    Run an offline ASO audit on canonical App Store metadata under ./Store and surface keyword gaps using Astro MCP.

    239 GitHub starsUsed in 6 repos~2.6k tokens
    Auto-check passed

Categories

Questions about Audit Xcode Security Settings

What does Audit Xcode Security Settings do?

Audit and enable security-oriented Xcode build settings, compiler warnings, static analysis, and Enhanced Security features. Audit Xcode Security Settings is an agent skill from CamilleScholtz/swmpc. Audit and enable security-oriented Xcode build settings, compiler warnings, static analysis, and Enhanced Security features.

When should I use Audit Xcode Security Settings?

Audit Xcode Security Settings fits situations like: tasks that involve iOS development.

How do I install Audit Xcode Security Settings in Claude Code?

Run `npx skills add CamilleScholtz/swmpc --skill audit-xcode-security-settings -a claude-code`. Or copy the skill folder (.agents/skills/audit-xcode-security-settings in CamilleScholtz/swmpc) into .claude/skills/audit-xcode-security-settings in your project. Claude Code loads it when a task matches its description.

How do I install Audit Xcode Security Settings in Codex?

Run `npx skills add CamilleScholtz/swmpc --skill audit-xcode-security-settings -a codex`. Or copy the skill folder (.agents/skills/audit-xcode-security-settings in CamilleScholtz/swmpc) into .agents/skills/audit-xcode-security-settings in your project. Codex loads it when a task matches its description.

Can I use Audit Xcode Security Settings in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add CamilleScholtz/swmpc --skill audit-xcode-security-settings -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-xcode-security-settings, .gemini/skills/audit-xcode-security-settings, .github/skills/audit-xcode-security-settings and .opencode/skills/audit-xcode-security-settings in your project.

What does Audit Xcode Security Settings need to run?

Going by SKILL.md and its folder, Audit Xcode Security Settings needs Python for the scripts in its folder and the command-line tools its instructions call (xcodebuild and python3). Our summary lists: Python 3.

Does Audit Xcode Security Settings access the network?

SKILL.md names 1 domain. In commands or code: clang.llvm.org; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Audit Xcode Security Settings safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Audit Xcode Security Settings use?

Audit Xcode Security Settings is published under the EUPL-1.2 licence (the repository's licence).

How many tokens does Audit Xcode Security Settings use?

About 12k tokens (SKILL.md is roughly 50k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 17k tokens, read only when the agent opens those files.

What are the alternatives to Audit Xcode Security Settings?

Skills that share tags, products or a category with Audit Xcode Security Settings: Update Swiftui APIs (AvdLee/SwiftUI-Agent-Skill, 3.7k stars), iOS Simulator Skill (conorluddy/ios-simulator-skill, 1.3k stars), Inspector MCP (ipedro/Inspector, 170 stars) and Xcode Build (pzep1/xcode-build-skill, 138 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Xcode Security Settings?

CamilleScholtz (a GitHub user) maintains it in CamilleScholtz/swmpc, which has 239 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on October 6, 2026.

Source: CamilleScholtz/swmpc on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.