Agent skill

macOS Permissions

by daymade in daymade/claude-code-skills

Diagnoses and repairs macOS TCC dialogs and silent denials: Full Disk Access, Screen Recording, Microphone, Camera, Accessibility, Automation.

MITAuto-check: notesFrontend & Design

Install macOS Permissions

skills CLI
$ npx skills add daymade/claude-code-skills --skill macos-permissions -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install daymade/claude-code-skills macos-permissions --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/daymade/claude-code-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/daymade-macos/macos-permissions .claude/skills/macos-permissions && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
macos-permissions
GitHub stars
1.4k
Token cost
~1.3k tokens
SKILL.md length
591 words
Files
4 (incl. references)
Skills in repo
103
Repo updated
First seen
Licence
MIT

At a glance

Diagnoses and repairs macOS TCC dialogs and silent denials: Full Disk Access, Screen Recording, Microphone, Camera, Accessibility, Automation.

  • Recurring prompts
  • SKILL.md covers The attribution trap, Decision tree, Core rules (each from a real… and Scope
  • Calls uv
  • LaunchAgent/uv jobs that fail only in background

What it does

macOS Permissions is an agent skill from daymade/claude-code-skills. Diagnoses and repairs macOS TCC dialogs and silent denials: Full Disk Access, Screen Recording, Microphone, Camera, Accessibility, Automation. Use for recurring prompts, LaunchAgent/uv jobs that fail only in background, broken grants, or automating Full Disk Access (权限弹窗 / 授权了没用 / 完全磁盘访问). Checks requester and grants first. Not for launchd design (macos-watchdog) or app permission UX (developing-ios-apps).

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/automated-full-disk-access.md`, `references/tcc-mechanics.md` and `references/uv-fda-trap.md`).

It sits in Frontend & Design, covering iOS development. It works with macOS. The repository describes itself as: Professional Claude Code skills marketplace featuring production-ready skills for enhanced development workflows. The licence is MIT.

When your agent uses it

  • Recurring prompts
  • LaunchAgent/uv jobs that fail only in background
  • Automating Full Disk Access (权限弹窗 / 授权了没用 / 完全磁盘访问)

Example prompts

  • “Use the macos-permissions skill to diagnose and repairs macOS TCC dialogs and silent denials: Full Disk Access, Screen Recording, Microphone…”
  • “/macos-permissions”

What it can do on your machine

Read from SKILL.md and the folder at commit 872127b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • uv

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

macOS Permissions loads about 1.3k tokens when it runs, and up to ~5.8k if it reads all its reference files. Until then it costs about 107 tokens; SKILL.md has 591 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~107
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:40
    sudo -n sqlite3 '/Library/Application Support/com.apple.TCC/TCC.db' \

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from daymade/claude-code-skills at commit 872127b, republished under its MIT licence (© daymade). 591 words, ~1,345 tokens.

Download SKILL.mdSave it as .claude/skills/macos-permissions/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
macos-permissions
description
Diagnoses and repairs macOS TCC dialogs and silent denials: Full Disk Access, Screen Recording, Microphone, Camera, Accessibility, Automation. Use for recurring prompts, LaunchAgent/uv jobs that fail only in background, broken grants, or automating Full Disk Access (权限弹窗 / 授权了没用 / 完全磁盘访问). Checks requester and grants first. Not for launchd design (macos-watchdog) or app permission UX (developing-ios-apps).

macOS Permissions (TCC)

macOS gates per-app, per-resource access through TCC (Transparency, Consent, Control). TCC records permission decisions in its databases and controls what a process can do. Several common traps need different fixes:

TrapSymptomFix lives in
Wrong subject grantedDialog names python3.11/2.1.232/node; you granted that but it still promptsThe attribution trap below
Grant doesn't surviveWorked, then a binary/uv/CLI update → prompt returnsreferences/uv-fda-trap.md
Silent denialFeature "unavailable", no dialog, grant looks ONreferences/tcc-mechanics.md § auth_value
Can't read TCC.dbPermission denied reading the DB; need FDA to diagnose FDAreferences/tcc-mechanics.md § SIP

The attribution trap

The name in the dialog does not prove who to grant. macOS attributes a request to the responsible process in the process tree, but displays the name of the accessing executable — and for an unsigned binary with no bundle (uv-managed python, per-version CLI, node helpers) that display name is just the last path component, which changes with every version. Granting the displayed name is the mistake that costs the most rounds.

Before touching System Settings, inspect the request and any readable grant state:

bash
# 1. Who is actually requesting — the responsible process in the attribution chain
/usr/bin/log show --last 30m --predicate 'subsystem == "com.apple.TCC"' --info --debug \
  | grep -E 'from Sub:|responsible=|accessing=' | tail -20

# 2. Grant candidates, if this terminal can read the system database
sudo -n sqlite3 '/Library/Application Support/com.apple.TCC/TCC.db' \
  "select service, client, auth_value from access where service='kTCCServiceSystemPolicyAllFiles' and client like '%<name>%';"

Use from Sub: to identify a candidate requester, then verify its exact path and a real protected read before choosing what to authorize. An unreadable TCC.db leaves grant state unknown; its FDA bootstrap is in references/tcc-mechanics.md.

Decision tree

The situation is…Go to
User asks to complete Full Disk Access repair automatically, or a background job needs protected filesreferences/automated-full-disk-access.md (reuse a verified existing grant first; otherwise drive System Settings and read back)
Dialog reappears after clicking Allow; or a LaunchAgent / uv run job prompts every few minutesreferences/uv-fda-trap.md (identify the requester; follow the automated repair route before adding a grant)
Need the full kTCCService catalog, schema, auth_value/auth_reason semantics, tccutilreferences/tcc-mechanics.md
Reading TCC.db gives "Permission denied"references/tcc-mechanics.md § SIP and the FDA bootstrap
A granted permission silently stopped working after an updatereferences/tcc-mechanics.md § common failure modes (toggle off/on, or tccutil reset <Service> <bundle-id>)
Grant won't stick for Automation / Apple Eventsreferences/tcc-mechanics.md — BOTH controller AND target need the grant
Show full SKILL.md (256 more words)Show less

Core rules (each from a real incident)

  • Dialog name ≠ responsible process. from Sub: in the TCC log is the requester; the title is the accessing binary's basename and it drifts with versions. Grant by the real path. (2026-09-19: a uv FDA dialog showed python3.11; authorizing python, changing session type, and pinning the version all failed because the requester was ~/.local/bin/uv.)
  • Grants are keyed to the exact binary path, not identity. An unsigned executable (uv-managed python, per-version CLI, node helper) is a new app to TCC every time its path changes. This is why "worked yesterday, prompts today" after any update. Same root cause as Claude Code issues #74234 / #84948 / #86706.
  • "0 hits / can't catch it" is an instrument problem, not a conclusion. fs_usage can emit 0 bytes on some machines; short-lived processes fall between log time windows; an empty grep file looks identical to a real zero. To pin which operation triggers a prompt, use in-process sys.addaudithook to log open events aligned to the tccd timestamp — not fs_usage.
  • SIP protects the system TCC.db read-only. You cannot INSERT/UPDATE a grant from the command line — authorization must go through the GUI. auth_value is readable, writable is not.
  • After granting, restart the requesting process. Grants are read at launch; a running process keeps its old (denied) state until relaunched.

Scope

This skill owns permission diagnosis and repair. It does not own: building an app's permission-onboarding UX (app-development work, out of scope here), launchd job design (macos-watchdog), or disk cleanup (macos-cleaner) — those link here when they hit a TCC wall.

© daymade, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in daymade-macos/macos-permissions of daymade/claude-code-skills.

  • SKILL.md
  • references/automated-full-disk-access.md
  • references/tcc-mechanics.md
  • references/uv-fda-trap.md

Open the folder on GitHubat commit 872127b

Compare with similar skills

macOS Permissions next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

macOS Permissions compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
macOS Permissions this skilldaymade/claude-code-skills1.4k—~1.3kAutomated safety check: NotesMIT
Wayfinder Codex UX Reviewasdecided/WayfinderRouter417—~1.1kAutomated safety check: PassApache-2.0
UI Review TahoeKartikLabhshetwar/better-shot2.4k2 repos~1.7kAutomated safety check: PassCustom licence
App Icon Generatorrshankras/claude-code-apple-skills785—~5.1kAutomated safety check: NotesMIT
iOS Patternshanamizuki/solopreneur152—~2.3kAutomated safety check: NotesMIT
macOS Golden Gate Designgithub/awesome-copilot40k—~2.1kAutomated safety check: PassMIT

Similar skills

  • Wayfinder Codex UX Review

    asdecided/WayfinderRouter

    Review and improve WAYFINDER's native macOS UX against OpenAI Codex app patterns and the repo's accepted menu-bar design contracts.

    417 GitHub stars~1.1k tokensUpdated 4 days ago
    Frontend & DesignAuto-check passed
  • UI Review Tahoe

    KartikLabhshetwar/better-shot

    Comprehensive UI/UX review for macOS Tahoe apps. An agent skill from KartikLabhshetwar/better-shot.

    2.4k GitHub starsUsed in 2 repos~1.7k tokens
    Frontend & DesignAuto-check passed
  • App Icon Generator

    rshankras/claude-code-apple-skills

    Generates an app icon for macOS or iOS — a fast CoreGraphics placeholder and/or flat layered source art to finish in Icon Composer (the Liquid Glass / iOS 26+ standard).

    785 GitHub stars~5.1k tokensUpdated 2 mo ago
    Frontend & DesignAuto-check: notes
  • iOS Patterns

    hanamizuki/solopreneur

    A skill your agent uses when building iOS/macOS apps with SwiftUI — covers localization (String Catalogs), date/time formatting, JSON date decoding, Previews, state management, sheet/navigation…

    152 GitHub stars~2.3k tokensUpdated 13 days ago
    Frontend & DesignAuto-check: notes
  • macOS Golden Gate Design

    github/awesome-copilot

    Official

    Design, implement, review, or refactor native macOS 27 Golden Gate interfaces in SwiftUI or AppKit.

    40k GitHub stars~2.1k tokensUpdated today
    Frontend & DesignAuto-check passed
  • Localization Setup

    rshankras/claude-code-apple-skills

    Generate internationalization (i18n) infrastructure for multi-language support in iOS/macOS apps.

    785 GitHub stars~1.4k tokensUpdated 2 mo ago
    Frontend & DesignAuto-check: notes

More from daymade/claude-code-skills

All 103 skills in this repo
  • Video Comparer

    daymade/claude-code-skills

    This skill should be used when comparing two videos to analyze compression results or quality differences.

    1.4k GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check: notes
  • CLI Demo Generator

    daymade/claude-code-skills

    Generates professional animated CLI demos as GIFs using VHS terminal recordings.

    1.4k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Doc To Markdown

    daymade/claude-code-skills

    Converts DOCX/PDF/PPTX and saved HTML/HTM to high-quality Markdown with automatic post-processing.

    1.4k GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Interaction Design Board

    daymade/claude-code-skills

    Generates several distinct, clickable HTML interaction prototypes for one product surface into a Design Board and collects selection/remix feedback before implementation.

    1.4k GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Auto Repo Setup

    daymade/claude-code-skills

    Diagnoses and repairs repository setup and guarded Git workflows for Claude Code or Codex — environment repair, startup sync, hook auditing, collaborator handoff.

    1.4k GitHub stars~2.8k tokensUpdated today
    Auto-check: notes
  • Bigdata Skill

    daymade/claude-code-skills

    Pulls Bigdata.com (RavenPack) financial and news data via the official bigdata-client SDK and /v1/ REST endpoints — structured financials, prices, analyst estimates, entity-sentiment series…

    1.4k GitHub stars~3.7k tokensUpdated today
    Auto-check passed

Works with

Questions about macOS Permissions

What does macOS Permissions do?

Diagnoses and repairs macOS TCC dialogs and silent denials: Full Disk Access, Screen Recording, Microphone, Camera, Accessibility, Automation. macOS Permissions is an agent skill from daymade/claude-code-skills. Diagnoses and repairs macOS TCC dialogs and silent denials: Full Disk Access, Screen Recording, Microphone, Camera, Accessibility, Automation.

When should I use macOS Permissions?

macOS Permissions fits situations like: recurring prompts; launchAgent/uv jobs that fail only in background; automating Full Disk Access (权限弹窗 / 授权了没用 / 完全磁盘访问).

How do I install macOS Permissions in Claude Code?

Run `npx skills add daymade/claude-code-skills --skill macos-permissions -a claude-code`. Or copy the skill folder (daymade-macos/macos-permissions in daymade/claude-code-skills) into .claude/skills/macos-permissions in your project. Claude Code loads it when a task matches its description.

How do I install macOS Permissions in Codex?

Run `npx skills add daymade/claude-code-skills --skill macos-permissions -a codex`. Or copy the skill folder (daymade-macos/macos-permissions in daymade/claude-code-skills) into .agents/skills/macos-permissions in your project. Codex loads it when a task matches its description.

Can I use macOS Permissions in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add daymade/claude-code-skills --skill macos-permissions -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/macos-permissions, .gemini/skills/macos-permissions, .github/skills/macos-permissions and .opencode/skills/macos-permissions in your project.

What does macOS Permissions need to run?

Going by SKILL.md and its folder, macOS Permissions needs the command-line tools its instructions call (uv).

Does macOS Permissions access the network?

SKILL.md contains no URLs. Its commands use uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is macOS Permissions safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does macOS Permissions use?

macOS Permissions is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does macOS Permissions use?

About 1.3k tokens (SKILL.md is roughly 5.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.5k tokens, read only when the agent opens those files.

What are the alternatives to macOS Permissions?

Skills that share tags, products or a category with macOS Permissions: Wayfinder Codex UX Review (asdecided/WayfinderRouter, 417 stars), UI Review Tahoe (KartikLabhshetwar/better-shot, 2.4k stars), App Icon Generator (rshankras/claude-code-apple-skills, 785 stars) and iOS Patterns (hanamizuki/solopreneur, 152 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains macOS Permissions?

daymade (a GitHub user) maintains it in daymade/claude-code-skills, which has 1,447 GitHub stars. The repository holds 103 skills in this directory. The repository was last updated on October 9, 2026.

Source: daymade/claude-code-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.