Agent skill

Device Integrity

by dpearson2699 in dpearson2699/swift-ios-skills

Verify device legitimacy and app integrity using DeviceCheck (DCDevice per-device bits) and App Attest (DCAppAttestService key generation, attestation, and assertion flows).

Custom licenceAuto-check passedBackend & APIs

Install Device Integrity

skills CLI
$ npx skills add dpearson2699/swift-ios-skills --skill device-integrity -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dpearson2699/swift-ios-skills device-integrity --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dpearson2699/swift-ios-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/device-integrity .claude/skills/device-integrity && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
device-integrity
GitHub stars
1.2k
Token cost
~4.4k tokens
SKILL.md length
1,146 words
Files
3 (incl. references)
Skills in repo
86
Repo updated
First seen
Licence
Custom licence

At a glance

Verify device legitimacy and app integrity using DeviceCheck (DCDevice per-device bits) and App Attest (DCAppAttestService key generation, attestation, and assertion flows).

  • Works in 3 steps: Key generation -- create a key pair in… → Attestation -- Apple certifies the key… → Assertion -- sign server requests with…
  • Implementing fraud prevention
  • SKILL.md covers Contents, DCDevice (DeviceCheck Tokens), DCAppAttestService (App Attest) and App Attest Key Generation, plus 8 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Device Integrity is an agent skill from dpearson2699/swift-ios-skills. Verify device legitimacy and app integrity using DeviceCheck (DCDevice per-device bits) and App Attest (DCAppAttestService key generation, attestation, and assertion flows). Use when implementing fraud prevention, detecting compromised devices, validating app authenticity with Apple's servers, protecting sensitive API endpoints with attested requests, or adding device verification to a backend architecture.

Its SKILL.md is about 4.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `evals/evals.json` and `references/device-integrity-patterns.md`).

It sits in Backend & APIs, covering Backend development and REST APIs. The repository describes itself as: Agent Skills for iOS 26+, Swift 6.3, SwiftUI, and modern Apple frameworks.

When your agent uses it

  • Implementing fraud prevention
  • Detecting compromised devices
  • Validating app authenticity with Apples servers
  • Protecting sensitive API endpoints with attested requests

Example prompts

  • “/device-integrity”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Key generation -- create a key pair in the Secure Enclave.
  2. Attestation -- Apple certifies the key belongs to a genuine Apple device running your app.
  3. Assertion -- sign server requests with the attested key to prove ongoing legitimacy.

What it can do on your machine

Read from SKILL.md and the folder at commit 8d90fd1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are swift).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • sosumi.ai

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Device Integrity loads about 4.4k tokens when it runs, and up to ~7.2k if it reads all its reference files. Until then it costs about 107 tokens; SKILL.md has 1,146 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~107
When it runs · the whole SKILL.md, loaded when a task matches
~4.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 1,146 words (~4,419 tokens).

“Verify that requests to your server come from a genuine Apple device running a legitimate instance of your app. DeviceCheck provides per-device bits for simple flags (e.g., "claimed promo offer"). App Attest uses Secure Enclave keys and Apple attestation to…”

— opening of SKILL.md by dpearson2699, Custom licence
name
device-integrity

Read the full SKILL.md on GitHub

Files

SKILL.md and 2 other files (references) in skills/device-integrity of dpearson2699/swift-ios-skills.

  • SKILL.md
  • evals/evals.json
  • references/device-integrity-patterns.md

Open the folder on GitHubat commit 8d90fd1

Compare with similar skills

Device Integrity next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Device Integrity compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Device Integrity this skilldpearson2699/swift-ios-skills1.2k—~4.4kAutomated safety check: PassCustom licence
Nodejs Backend Patternsever-works/ever-works15818 repos~4kAutomated safety check: PassAGPL-3.0
Pangolin CRUD Endpointsfosrl/pangolin23k—~461Automated safety check: PassCustom licence
Fastcrudbenavlabs/fastcrud1.6k—~5kAutomated safety check: PassMIT
Dr Jskilljdubois/dr-jskill342—~4.6kAutomated safety check: NotesApache-2.0
Laravel SpecialistJeffallan/claude-skills12k1 repos~2.1kAutomated safety check: PassMIT

Similar skills

  • Nodejs Backend Patterns

    ever-works/ever-works

    Build production-ready Node.js backend services with Express/Fastify, implementing middleware patterns, error handling, authentication, database integration, and API design best practices.

    158 GitHub starsUsed in 18 repos~4k tokens
    Backend & APIsAuto-check passed
  • Use whenever asked to add, create, or scaffold a CRUD endpoint, router, or entity in this repo's server (create/list/get/update/delete handlers, new…

    23k GitHub stars~461 tokensUpdated today
    Backend & APIsAuto-check passed
  • Fastcrud

    benavlabs/fastcrud

    A skill your agent uses when building or modifying CRUD endpoints with FastCRUD (the fastcrud PyPI package) in a FastAPI project — covers FastCRUD, crudrouter, EndpointCreator, FilterConfig…

    1.6k GitHub stars~5k tokensUpdated 13 days ago
    Backend & APIsAuto-check passed
  • Dr Jskill

    jdubois/dr-jskill

    Creates Java + Spring Boot projects: Web applications, full-stack apps with Vue.js or Angular or React or vanilla JS, PostgreSQL, REST APIs, and Docker.

    342 GitHub stars~4.6k tokensUpdated 8 days ago
    Backend & APIsAuto-check: notes
  • Laravel Specialist

    Jeffallan/claude-skills

    Builds Laravel 10+ applications with Eloquent models, Sanctum authentication, Horizon queues, API resources and Livewire components, tested with Pest or PHPUnit.

    12k GitHub starsUsed in 1 repo~2.1k tokens
    Backend & APIsAuto-check passed
  • Grails Developer Guide

    apache/grails-core

    Guides building Grails web applications and REST APIs with GORM, controllers, services, views, plugins and Spock and Geb testing.

    2.9k GitHub stars~4.9k tokensUpdated today
    Backend & APIsAuto-check passed

More from dpearson2699/swift-ios-skills

All 86 skills in this repo
  • iOS Memgraph Analysis

    dpearson2699/swift-ios-skills

    A skill your agent uses when capturing or analyzing an iOS .memgraph, especially when the task mentions a memory leak, heap growth, persistent memory increase, ownership path, or matched-capture…

    1.2k GitHub stars~2.4k tokensUpdated 2 mo ago
    Auto-check passed
  • Natural Language

    dpearson2699/swift-ios-skills

    Tokenize, tag, and analyze natural language text using Apple's NaturalLanguage framework and translate between languages with the Translation framework.

    1.2k GitHub starsUsed in 1 repo~3.5k tokens
    Auto-check passed
  • iOS Ettrace Performance

    dpearson2699/swift-ios-skills

    A skill your agent uses when capturing or analyzing ETTrace profiles for a focused iOS launch or runtime flow, including exact-build dSYM UUID matching, Simulator or device capture, processed…

    1.2k GitHub stars~2.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Accessorysetupkit

    dpearson2699/swift-ios-skills

    Discover and configure Bluetooth and Wi-Fi accessories using AccessorySetupKit.

    1.2k GitHub stars~3.5k tokensUpdated 2 mo ago
    Auto-check passed
  • Activitykit

    dpearson2699/swift-ios-skills

    Implement, review, or improve Live Activities and Dynamic Island experiences in iOS apps using ActivityKit.

    1.2k GitHub stars~4.6k tokensUpdated 2 mo ago
    Auto-check passed
  • Adattributionkit

    dpearson2699/swift-ios-skills

    Measure ad effectiveness with privacy-preserving attribution using AdAttributionKit.

    1.2k GitHub stars~3.5k tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Device Integrity

What does Device Integrity do?

Verify device legitimacy and app integrity using DeviceCheck (DCDevice per-device bits) and App Attest (DCAppAttestService key generation, attestation, and assertion flows). Device Integrity is an agent skill from dpearson2699/swift-ios-skills. Verify device legitimacy and app integrity using DeviceCheck (DCDevice per-device bits) and App Attest (DCAppAttestService key generation, attestation, and assertion flows).

When should I use Device Integrity?

Device Integrity fits situations like: implementing fraud prevention; detecting compromised devices; validating app authenticity with Apples servers; protecting sensitive API endpoints with attested requests.

How do I install Device Integrity in Claude Code?

Run `npx skills add dpearson2699/swift-ios-skills --skill device-integrity -a claude-code`. Or copy the skill folder (skills/device-integrity in dpearson2699/swift-ios-skills) into .claude/skills/device-integrity in your project. Claude Code loads it when a task matches its description.

How do I install Device Integrity in Codex?

Run `npx skills add dpearson2699/swift-ios-skills --skill device-integrity -a codex`. Or copy the skill folder (skills/device-integrity in dpearson2699/swift-ios-skills) into .agents/skills/device-integrity in your project. Codex loads it when a task matches its description.

Can I use Device Integrity in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dpearson2699/swift-ios-skills --skill device-integrity -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/device-integrity, .gemini/skills/device-integrity, .github/skills/device-integrity and .opencode/skills/device-integrity in your project.

What does Device Integrity need to run?

SKILL.md names no scripts, command-line tools or credentials: Device Integrity is instructions for the agent only.

Does Device Integrity access the network?

SKILL.md names 1 domain. As links in the text: sosumi.ai. This is read from the text; nothing was executed.

Is Device Integrity safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Device Integrity use?

Device Integrity has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Device Integrity use?

About 4.4k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.8k tokens, read only when the agent opens those files.

What are the alternatives to Device Integrity?

Skills that share tags, products or a category with Device Integrity: Nodejs Backend Patterns (ever-works/ever-works, 158 stars), Pangolin CRUD Endpoints (fosrl/pangolin, 23k stars), Fastcrud (benavlabs/fastcrud, 1.6k stars) and Dr Jskill (jdubois/dr-jskill, 342 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Device Integrity?

dpearson2699 (a GitHub user) maintains it in dpearson2699/swift-ios-skills, which has 1,175 GitHub stars. The repository holds 86 skills in this directory. The repository was last updated on July 31, 2026.

Source: dpearson2699/swift-ios-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.