Agent skill

Swift Security

by dpearson2699 in dpearson2699/swift-ios-skills

A skill your agent uses when working with iOS/macOS Keychain Services (SecItem queries, kSecClass, OSStatus errors), biometric authentication (LAContext, Face ID, Touch ID), CryptoKit (AES-GCM…

MITAuto-check passedMobile

Install Swift Security

skills CLI
$ npx skills add dpearson2699/swift-ios-skills --skill swift-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dpearson2699/swift-ios-skills swift-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dpearson2699/swift-ios-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/swift-security .claude/skills/swift-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
swift-security
GitHub stars
1.2k
Token cost
~3.2k tokens
SKILL.md length
1,197 words
Files
16 (incl. references)
Skills in repo
86
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when working with iOS/macOS Keychain Services (SecItem queries, kSecClass, OSStatus errors), biometric authentication (LAContext, Face ID, Touch ID), CryptoKit (AES-GCM…

  • Works in 3 steps: Review existing code: run the Review… → Improve or migrate code: identify the… → Implement new security code: load the…
  • Working with iOS/macOS Keychain Services (SecItem queries
  • SKILL.md covers Contents, Workflow, Reference Loading and Security Invariants, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Swift Security is an agent skill from dpearson2699/swift-ios-skills. Use when working with iOS/macOS Keychain Services (SecItem queries, kSecClass, OSStatus errors), biometric authentication (LAContext, Face ID, Touch ID), CryptoKit (AES-GCM, ChaChaPoly, ECDSA, ECDH, HPKE, ML-KEM), Secure Enclave, secure credential storage (OAuth tokens, API keys), certificate pinning (SecTrust, SPKI), keychain sharing across apps/extensions, migrating secrets from UserDefaults or plists, or OWASP MASVS/MASTG mobile compliance on Apple platforms.

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 17 other files, including reference files (for example `evals/evals.json`, `references/biometric-authentication.md` and `references/certificate-trust.md`).

It sits in Mobile, covering iOS development and Web application vulnerabilities. It works with iOS and macOS. The repository describes itself as: Agent Skills for iOS 26+, Swift 6.3, SwiftUI, and modern Apple frameworks. The licence is MIT.

When your agent uses it

  • Working with iOS/macOS Keychain Services (SecItem queries
  • OSStatus errors)
  • Biometric authentication (LAContext
  • CryptoKit (AES-GCM

Example prompts

  • “/swift-security”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Review existing code: run the Review Checklist, then
  2. Improve or migrate code: identify the migration type, load the migration
  3. Implement new security code: load the minimum domain references, use the

What it can do on your machine

Read from SKILL.md and the folder at commit 8d90fd1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are swift).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Swift Security loads about 3.2k tokens when it runs, and up to ~123k if it reads all its reference files. Until then it costs about 120 tokens; SKILL.md has 1,197 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~120
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~123k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dpearson2699/swift-ios-skills at commit 8d90fd1, republished under its MIT licence (© dpearson2699). 1,197 words, ~3,245 tokens.

Download SKILL.mdSave it as .claude/skills/swift-security/SKILL.md (or your agent's skills folder). This skill also uses 15 other files; get the full folder from GitHub.
name
swift-security
description
Use when working with iOS/macOS Keychain Services (SecItem queries, kSecClass, OSStatus errors), biometric authentication (LAContext, Face ID, Touch ID), CryptoKit (AES-GCM, ChaChaPoly, ECDSA, ECDH, HPKE, ML-KEM), Secure Enclave, secure credential storage (OAuth tokens, API keys), certificate pinning (SecTrust, SPKI), keychain sharing across apps/extensions, migrating secrets from UserDefaults or plists, or OWASP MASVS/MASTG mobile compliance on Apple platforms.
license
MIT

Swift Security

Use this skill for client-side Apple platform security work: Keychain Services, access control, biometric-gated secrets, CryptoKit, Secure Enclave keys, credential storage, certificate trust, keychain sharing, legacy secret migration, security testing, and OWASP mobile compliance mapping.

Default to iOS 17+ and Swift concurrency examples when the deployment target is unknown. Keep iOS 13+ compatibility notes when the user asks for older targets. Treat iOS 26 CryptoKit post-quantum APIs as availability-gated.

Contents

Workflow

Classify the request before loading references.

  1. Review existing code: run the Review Checklist, then load common-anti-patterns.md plus the domain reference for each failing area. Report severity, evidence, and the corrected pattern.
  2. Improve or migrate code: identify the migration type, load the migration and target-domain references, preserve existing data, verify the new item, then remove legacy storage only after success.
  3. Implement new security code: load the minimum domain references, use the provided correct patterns, include OSStatus handling and tests, then run the relevant checklist.

Do not load every reference file by default. This skill is intentionally split for progressive disclosure; load only the files needed by the user's task.

Minimum Safe Keychain Write

Use separate add, identity, and update dictionaries; handle every OSStatus:

swift
func saveSecret(_ data: Data, account: String) throws {
    let identity: [CFString: Any] = [
        kSecClass: kSecClassGenericPassword,
        kSecAttrService: "com.example.app",
        kSecAttrAccount: account,
    ]
    var add = identity
    add[kSecValueData] = data
    add[kSecAttrAccessible] = kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly

    switch SecItemAdd(add as CFDictionary, nil) {
    case errSecSuccess:
        return
    case errSecDuplicateItem:
        let status = SecItemUpdate(
            identity as CFDictionary,
            [kSecValueData: data] as CFDictionary
        )
        guard status == errSecSuccess else { throw KeychainError(status: status) }
    case let status:
        throw KeychainError(status: status)
    }
}

Load keychain-fundamentals.md for read, delete, access-control, locked-device, and test patterns.

Reference Loading

If the task involvesLoad
General keychain CRUD or OSStatus handlingkeychain-fundamentals.md
Choosing kSecClass or item identitykeychain-item-classes.md
Accessibility classes or SecAccessControlkeychain-access-control.md
Face ID, Touch ID, or biometric-gated secretsbiometric-authentication.md
Secure Enclave keyssecure-enclave.md
Hashing, HMAC, AES-GCM, ChaChaPoly, HKDF, PBKDF2cryptokit-symmetric.md
Signing, ECDH, HPKE, ML-KEM, ML-DSAcryptokit-public-key.md
OAuth tokens, API keys, logout, refresh rotationcredential-storage-patterns.md
App/extension keychain sharingkeychain-sharing.md
Certificate trust, SPKI pinning, mTLScertificate-trust.md
UserDefaults/plist/NSCoding migrationmigration-legacy-stores.md
Unit, integration, simulator, device, or CI teststesting-security-code.md
OWASP MASVS/MASTG or enterprise audit mappingcompliance-owasp-mapping.md
Full security reviewcommon-anti-patterns.md, then each touched domain reference

Security Invariants

Use directive language only for these security invariants and the matching anti-patterns in common-anti-patterns.md. For architecture choices outside this list, use advisory language.

  • Never store tokens, passwords, API keys, signing keys, or refresh tokens in UserDefaults, Info.plist, .xcconfig, source code, logs, files, or NSCoding archives. Use Keychain or fetch secrets at runtime.
  • Never ignore OSStatus. Every SecItemAdd, SecItemCopyMatching, SecItemUpdate, and SecItemDelete path must handle success and expected failures such as errSecDuplicateItem, errSecItemNotFound, and errSecInteractionNotAllowed.
  • Never use LAContext.evaluatePolicy() as the only gate for a secret. Bind protected secrets to keychain items with SecAccessControl, then let keychain access trigger LocalAuthentication.
  • Always set kSecAttrAccessible or kSecAttrAccessControl explicitly when adding keychain items.
  • Always use add-or-update for persistent keychain writes. Do not delete-then-add as a normal update path.
  • Keep SecItem* work off the main actor. Use an actor or serial queue for keychain access.
  • On macOS AppKit targets, target the data protection keychain with kSecUseDataProtectionKeychain: true unless deliberately working with legacy file-based keychain items.
  • Never reuse an AES-GCM nonce with the same key.
  • Never use raw ECDH SharedSecret bytes as a symmetric key. Derive with HKDF or X9.63 derivation.
  • Never use Insecure.MD5 or Insecure.SHA1 for security purposes.

Sibling Boundaries

This skill owns client-side storage, cryptographic primitives, hardware-backed keys, and trust evaluation. Route adjacent work deliberately:

  • Use authentication for Sign in with Apple, passkeys, OAuth UI flows, ASAuthorizationController, credential state, and account sign-in UX.
  • Use cryptokit for primitive CryptoKit API syntax and examples when storage, key lifecycle, protocol/trust design, Secure Enclave policy, certificate trust, misuse review, or compliance is not part of the task.
  • Keep application-level E2E encryption security reviews here when the work involves key ownership, derivation, storage, rotation/recovery, Secure Enclave, HPKE/PQC migration, protocol trust boundaries, or misuse analysis.
  • Use device-integrity for DeviceCheck and App Attest attestation/assertion flows.
  • Use ios-networking for URLSession, request pipelines, ATS configuration, retries, caching, reachability, and transport architecture.
  • Use app-store-review for privacy manifests, ATT, App Review guideline compliance, and submission readiness.

This skill may mention those areas only to identify a security handoff.

Show full SKILL.md (546 more words)Show less

Review Checklist

Use this checklist for code reviews and migration plans. Mark each item pass, fail, or not applicable; for each failure, cite the reference file and severity.

  • Secrets are not stored in UserDefaults, plists, source, logs, files, or archives.
  • Every SecItem* call checks OSStatus and handles common recoverable errors.
  • Biometric access to secrets is keychain-bound with SecAccessControl, not a standalone Bool from LAContext.evaluatePolicy().
  • Keychain add dictionaries set an explicit accessibility policy.
  • Keychain writes use add-or-update rather than delete-then-add.
  • Keychain work is isolated from UI/main-actor code.
  • The selected kSecClass matches the item type and primary-key attributes.
  • CryptoKit code avoids nonce reuse, raw shared-secret use, weak hashes, and hardcoded keys.
  • Custom encryption designs identify key ownership, derivation, storage, rotation/recovery, availability gates, and protocol/trust boundaries.
  • Secure Enclave code checks availability, handles simulator/device differences, persists only dataRepresentation, and designs for device-bound keys.
  • App/extension sharing uses full Team ID access groups and matching entitlements on every target.
  • Certificate trust uses current SecTrust APIs, validates hostname/policy, and uses SPKI or CA pinning when pinning is required.
  • macOS keychain code intentionally chooses data protection or file-based keychain behavior.
  • Tests cover success, duplicate, missing item, locked-device, simulator/device, and migration paths where applicable.
  • OWASP MASVS/MASTG mappings are included when compliance is requested.

Common Mistakes

  • Generating partial keychain examples without duplicate handling or errSecItemNotFound handling.
  • Adding biometric UI but leaving the secret readable without keychain access control.
  • Choosing kSecAttrAccessibleWhenUnlocked implicitly by omitting the attribute.
  • Using kSecAttrAccessibleAlways or kSecAttrAccessibleAlwaysThisDeviceOnly, both deprecated.
  • Mixing kSecAttrAccessible and kSecAttrAccessControl on the same add query.
  • Treating Secure Enclave keys as importable, exportable, syncable, or suitable for symmetric encryption.
  • Claiming SHA-3, ML-KEM, ML-DSA, or X-Wing CryptoKit APIs are available before iOS 26.
  • Treating HPKE as available before iOS 17.
  • Implementing certificate pinning by hashing only raw key bytes instead of the correct SPKI representation.
  • Expanding this skill into account-login, networking, App Attest, or App Store review guidance instead of handing off to sibling skills.

Output Rules

  • For security findings, state severity: CRITICAL for exploitable secret or cryptography failures, HIGH for silent security boundary/data-loss issues, and MEDIUM for brittle or incomplete hardening.
  • Include wrong and corrected code examples for implementation reviews when a concrete anti-pattern is present.
  • Include minimum iOS/macOS availability when recommending versioned APIs.
  • Cite the reference file that supports each substantive security pattern.
  • For keychain code, include OSStatus handling and explicit accessibility in examples.
  • For implementation or migration answers, end with ## Reference Files and list the loaded references with a one-line purpose.
  • Do not invent WWDC session numbers or source citations. If a claim is not present in the loaded references or official Apple documentation, say it needs verification.

References

© dpearson2699, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 15 other files (references) in skills/swift-security of dpearson2699/swift-ios-skills.

  • SKILL.md
  • evals/evals.json
  • references/biometric-authentication.md
  • references/certificate-trust.md
  • references/common-anti-patterns.md
  • references/compliance-owasp-mapping.md
  • references/credential-storage-patterns.md
  • references/cryptokit-public-key.md
  • references/cryptokit-symmetric.md
  • references/keychain-access-control.md
  • references/keychain-fundamentals.md
  • references/keychain-item-classes.md
  • references/keychain-sharing.md
  • references/migration-legacy-stores.md
  • references/secure-enclave.md
  • references/testing-security-code.md

Open the folder on GitHubat commit 8d90fd1

Compare with similar skills

Swift Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Swift Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Swift Security this skilldpearson2699/swift-ios-skills1.2k—~3.2kAutomated safety check: PassMIT
Orca iOS Simulator Controlstablyai/orca87k1 repos~584Automated safety check: PassApache-2.0
Apple Crash Log .NET Symbolicationdotnet/skills5.6k1 repos~2.4kAutomated safety check: PassMIT
Swiftui Expert Skillomarshahine/HomeClaw1764 repos~2.8kAutomated safety check: PassMIT
Phoneagentrounak/PhoneAgent798—~2.2kAutomated safety check: PassMIT
Apple Designvrcm-team/VRCM1791 repos~6.2kAutomated safety check: PassMIT

Similar skills

  • iOS Simulator control from inside Orca, with the live device view in Orca's emulator pane. Use when driving a booted Apple Simulator on macOS: taps, gestures…

    87k GitHub starsUsed in 1 repo~584 tokens
    MobileAuto-check passed
  • Official

    Resolves .NET runtime frames in Apple .ips crash logs to function names, source files and line numbers using dSYM symbols, atos and the Microsoft symbol server.

    5.6k GitHub starsUsed in 1 repo~2.4k tokens
    MobileAuto-check passed
  • Swiftui Expert Skill

    omarshahine/HomeClaw

    A skill your agent uses when writing, reviewing, or refactoring SwiftUI code for iOS or macOS, including state management, view composition, performance, Liquid Glass adoption, or Instruments .trace…

    176 GitHub starsUsed in 4 repos~2.8k tokens
    MobileAuto-check passed
  • Phoneagent

    rounak/PhoneAgent

    Control a connected iPhone, iOS simulator, Android emulator, or Android device from macOS through PhoneAgent's JSON-RPC bridge.

    798 GitHub stars~2.2k tokensUpdated 1 mo ago
    MobileAuto-check passed
  • Apple Design

    vrcm-team/VRCM

    Cross-platform UI/UX design reviewer grounded in Apple's Human Interface Guidelines (122 pages pulled from developer.apple.com, including 57 component pages) plus a design-craft lens for…

    179 GitHub starsUsed in 1 repo~6.2k tokens
    MobileAuto-check passed
  • Hig Project Context

    raintree-technology/hig-doctor

    Create or update a shared Apple design context document that other HIG skills use to tailor guidance.

    143 GitHub starsUsed in 5 repos~1.2k tokens
    MobileAuto-check passed

More from dpearson2699/swift-ios-skills

All 86 skills in this repo
  • iOS Memgraph Analysis

    dpearson2699/swift-ios-skills

    A skill your agent uses when capturing or analyzing an iOS .memgraph, especially when the task mentions a memory leak, heap growth, persistent memory increase, ownership path, or matched-capture…

    1.2k GitHub stars~2.4k tokensUpdated 2 mo ago
    Auto-check passed
  • Natural Language

    dpearson2699/swift-ios-skills

    Tokenize, tag, and analyze natural language text using Apple's NaturalLanguage framework and translate between languages with the Translation framework.

    1.2k GitHub starsUsed in 1 repo~3.5k tokens
    Auto-check passed
  • iOS Ettrace Performance

    dpearson2699/swift-ios-skills

    A skill your agent uses when capturing or analyzing ETTrace profiles for a focused iOS launch or runtime flow, including exact-build dSYM UUID matching, Simulator or device capture, processed…

    1.2k GitHub stars~2.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Accessorysetupkit

    dpearson2699/swift-ios-skills

    Discover and configure Bluetooth and Wi-Fi accessories using AccessorySetupKit.

    1.2k GitHub stars~3.5k tokensUpdated 2 mo ago
    Auto-check passed
  • Activitykit

    dpearson2699/swift-ios-skills

    Implement, review, or improve Live Activities and Dynamic Island experiences in iOS apps using ActivityKit.

    1.2k GitHub stars~4.6k tokensUpdated 2 mo ago
    Auto-check passed
  • Adattributionkit

    dpearson2699/swift-ios-skills

    Measure ad effectiveness with privacy-preserving attribution using AdAttributionKit.

    1.2k GitHub stars~3.5k tokensUpdated 2 mo ago
    Auto-check passed

Works with

Questions about Swift Security

What does Swift Security do?

A skill your agent uses when working with iOS/macOS Keychain Services (SecItem queries, kSecClass, OSStatus errors), biometric authentication (LAContext, Face ID, Touch ID), CryptoKit (AES-GCM…. Swift Security is an agent skill from dpearson2699/swift-ios-skills. Use when working with iOS/macOS Keychain Services (SecItem queries, kSecClass, OSStatus errors), biometric authentication (LAContext, Face ID, Touch ID), CryptoKit (AES-GCM, ChaChaPoly, ECDSA, ECDH, HPKE, ML-KEM), Secure Enclave, secure credential storage (OAuth tokens, API keys), certificate pinning (SecTrust, SPKI), keychain sharing across apps/extensions, migrating secrets from UserDefaults or plists, or OWASP MASVS/MASTG mobile compliance on Apple platforms.

When should I use Swift Security?

Swift Security fits situations like: working with iOS/macOS Keychain Services (SecItem queries; OSStatus errors); biometric authentication (LAContext; cryptoKit (AES-GCM.

How do I install Swift Security in Claude Code?

Run `npx skills add dpearson2699/swift-ios-skills --skill swift-security -a claude-code`. Or copy the skill folder (skills/swift-security in dpearson2699/swift-ios-skills) into .claude/skills/swift-security in your project. Claude Code loads it when a task matches its description.

How do I install Swift Security in Codex?

Run `npx skills add dpearson2699/swift-ios-skills --skill swift-security -a codex`. Or copy the skill folder (skills/swift-security in dpearson2699/swift-ios-skills) into .agents/skills/swift-security in your project. Codex loads it when a task matches its description.

Can I use Swift Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dpearson2699/swift-ios-skills --skill swift-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/swift-security, .gemini/skills/swift-security, .github/skills/swift-security and .opencode/skills/swift-security in your project.

What does Swift Security need to run?

SKILL.md names no scripts, command-line tools or credentials: Swift Security is instructions for the agent only.

Does Swift Security access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Swift Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Swift Security use?

Swift Security is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Swift Security use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 120k tokens, read only when the agent opens those files.

What are the alternatives to Swift Security?

Skills that share tags, products or a category with Swift Security: Orca iOS Simulator Control (stablyai/orca, 87k stars), Apple Crash Log .NET Symbolication (dotnet/skills, 5.6k stars), Swiftui Expert Skill (omarshahine/HomeClaw, 176 stars) and Phoneagent (rounak/PhoneAgent, 798 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Swift Security?

dpearson2699 (a GitHub user) maintains it in dpearson2699/swift-ios-skills, which has 1,175 GitHub stars. The repository holds 86 skills in this directory. The repository was last updated on July 31, 2026.

Source: dpearson2699/swift-ios-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.