Orca iOS Simulator Control
stablyai/orca
iOS Simulator control from inside Orca, with the live device view in Orca's emulator pane. Use when driving a booted Apple Simulator on macOS: taps, gestures…
A skill your agent uses when working with iOS/macOS Keychain Services (SecItem queries, kSecClass, OSStatus errors), biometric authentication (LAContext, Face ID, Touch ID), CryptoKit (AES-GCM…
$ npx skills add dpearson2699/swift-ios-skills --skill swift-security -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install dpearson2699/swift-ios-skills swift-security --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/dpearson2699/swift-ios-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/swift-security .claude/skills/swift-security && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "swift-security" agent skill from https://github.com/dpearson2699/swift-ios-skills/tree/main/skills/swift-security into .claude/skills/swift-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "swift-security", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/dpearson2699/swift-ios-skills/tree/main/skills/swift-securityType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add dpearson2699/swift-ios-skills --skill swift-security -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install dpearson2699/swift-ios-skills swift-security --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dpearson2699/swift-ios-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/swift-security .agents/skills/swift-security && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "swift-security" agent skill from https://github.com/dpearson2699/swift-ios-skills/tree/main/skills/swift-security into .agents/skills/swift-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "swift-security", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dpearson2699/swift-ios-skills --skill swift-security -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install dpearson2699/swift-ios-skills swift-security --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dpearson2699/swift-ios-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/swift-security .cursor/skills/swift-security && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "swift-security" agent skill from https://github.com/dpearson2699/swift-ios-skills/tree/main/skills/swift-security into .cursor/skills/swift-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "swift-security", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/dpearson2699/swift-ios-skills.git --path skills/swift-security--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add dpearson2699/swift-ios-skills --skill swift-security -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install dpearson2699/swift-ios-skills swift-security --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dpearson2699/swift-ios-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/swift-security .gemini/skills/swift-security && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "swift-security" agent skill from https://github.com/dpearson2699/swift-ios-skills/tree/main/skills/swift-security into .gemini/skills/swift-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "swift-security", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install dpearson2699/swift-ios-skills swift-securityInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add dpearson2699/swift-ios-skills --skill swift-security -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/dpearson2699/swift-ios-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/swift-security .github/skills/swift-security && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "swift-security" agent skill from https://github.com/dpearson2699/swift-ios-skills/tree/main/skills/swift-security into .github/skills/swift-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "swift-security", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dpearson2699/swift-ios-skills --skill swift-security -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install dpearson2699/swift-ios-skills swift-security --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dpearson2699/swift-ios-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/swift-security .opencode/skills/swift-security && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "swift-security" agent skill from https://github.com/dpearson2699/swift-ios-skills/tree/main/skills/swift-security into .opencode/skills/swift-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "swift-security", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
swift-securityA skill your agent uses when working with iOS/macOS Keychain Services (SecItem queries, kSecClass, OSStatus errors), biometric authentication (LAContext, Face ID, Touch ID), CryptoKit (AES-GCM…
Swift Security is an agent skill from dpearson2699/swift-ios-skills. Use when working with iOS/macOS Keychain Services (SecItem queries, kSecClass, OSStatus errors), biometric authentication (LAContext, Face ID, Touch ID), CryptoKit (AES-GCM, ChaChaPoly, ECDSA, ECDH, HPKE, ML-KEM), Secure Enclave, secure credential storage (OAuth tokens, API keys), certificate pinning (SecTrust, SPKI), keychain sharing across apps/extensions, migrating secrets from UserDefaults or plists, or OWASP MASVS/MASTG mobile compliance on Apple platforms.
Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 17 other files, including reference files (for example `evals/evals.json`, `references/biometric-authentication.md` and `references/certificate-trust.md`).
It sits in Mobile, covering iOS development and Web application vulnerabilities. It works with iOS and macOS. The repository describes itself as: Agent Skills for iOS 26+, Swift 6.3, SwiftUI, and modern Apple frameworks. The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 8d90fd1. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are swift).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Swift Security loads about 3.2k tokens when it runs, and up to ~123k if it reads all its reference files. Until then it costs about 120 tokens; SKILL.md has 1,197 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from dpearson2699/swift-ios-skills at commit 8d90fd1, republished under its MIT licence (© dpearson2699). 1,197 words, ~3,245 tokens.
.claude/skills/swift-security/SKILL.md (or your agent's skills folder). This skill also uses 15 other files; get the full folder from GitHub.Use this skill for client-side Apple platform security work: Keychain Services, access control, biometric-gated secrets, CryptoKit, Secure Enclave keys, credential storage, certificate trust, keychain sharing, legacy secret migration, security testing, and OWASP mobile compliance mapping.
Default to iOS 17+ and Swift concurrency examples when the deployment target is unknown. Keep iOS 13+ compatibility notes when the user asks for older targets. Treat iOS 26 CryptoKit post-quantum APIs as availability-gated.
Classify the request before loading references.
Do not load every reference file by default. This skill is intentionally split for progressive disclosure; load only the files needed by the user's task.
Use separate add, identity, and update dictionaries; handle every OSStatus:
func saveSecret(_ data: Data, account: String) throws {
let identity: [CFString: Any] = [
kSecClass: kSecClassGenericPassword,
kSecAttrService: "com.example.app",
kSecAttrAccount: account,
]
var add = identity
add[kSecValueData] = data
add[kSecAttrAccessible] = kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly
switch SecItemAdd(add as CFDictionary, nil) {
case errSecSuccess:
return
case errSecDuplicateItem:
let status = SecItemUpdate(
identity as CFDictionary,
[kSecValueData: data] as CFDictionary
)
guard status == errSecSuccess else { throw KeychainError(status: status) }
case let status:
throw KeychainError(status: status)
}
}Load keychain-fundamentals.md for read, delete, access-control, locked-device, and test patterns.
| If the task involves | Load |
|---|---|
| General keychain CRUD or OSStatus handling | keychain-fundamentals.md |
Choosing kSecClass or item identity | keychain-item-classes.md |
Accessibility classes or SecAccessControl | keychain-access-control.md |
| Face ID, Touch ID, or biometric-gated secrets | biometric-authentication.md |
| Secure Enclave keys | secure-enclave.md |
| Hashing, HMAC, AES-GCM, ChaChaPoly, HKDF, PBKDF2 | cryptokit-symmetric.md |
| Signing, ECDH, HPKE, ML-KEM, ML-DSA | cryptokit-public-key.md |
| OAuth tokens, API keys, logout, refresh rotation | credential-storage-patterns.md |
| App/extension keychain sharing | keychain-sharing.md |
| Certificate trust, SPKI pinning, mTLS | certificate-trust.md |
| UserDefaults/plist/NSCoding migration | migration-legacy-stores.md |
| Unit, integration, simulator, device, or CI tests | testing-security-code.md |
| OWASP MASVS/MASTG or enterprise audit mapping | compliance-owasp-mapping.md |
| Full security review | common-anti-patterns.md, then each touched domain reference |
Use directive language only for these security invariants and the matching anti-patterns in common-anti-patterns.md. For architecture choices outside this list, use advisory language.
UserDefaults, Info.plist, .xcconfig, source code, logs, files, or
NSCoding archives. Use Keychain or fetch secrets at runtime.OSStatus. Every SecItemAdd, SecItemCopyMatching,
SecItemUpdate, and SecItemDelete path must handle success and expected
failures such as errSecDuplicateItem, errSecItemNotFound, and
errSecInteractionNotAllowed.LAContext.evaluatePolicy() as the only gate for a secret. Bind
protected secrets to keychain items with SecAccessControl, then let
keychain access trigger LocalAuthentication.kSecAttrAccessible or kSecAttrAccessControl explicitly when
adding keychain items.SecItem* work off the main actor. Use an actor or serial queue for
keychain access.kSecUseDataProtectionKeychain: true unless deliberately working with
legacy file-based keychain items.SharedSecret bytes as a symmetric key. Derive with HKDF
or X9.63 derivation.Insecure.MD5 or Insecure.SHA1 for security purposes.This skill owns client-side storage, cryptographic primitives, hardware-backed keys, and trust evaluation. Route adjacent work deliberately:
authentication for Sign in with Apple, passkeys, OAuth UI flows,
ASAuthorizationController, credential state, and account sign-in UX.cryptokit for primitive CryptoKit API syntax and examples when storage,
key lifecycle, protocol/trust design, Secure Enclave policy, certificate
trust, misuse review, or compliance is not part of the task.device-integrity for DeviceCheck and App Attest attestation/assertion
flows.ios-networking for URLSession, request pipelines, ATS configuration,
retries, caching, reachability, and transport architecture.app-store-review for privacy manifests, ATT, App Review guideline
compliance, and submission readiness.This skill may mention those areas only to identify a security handoff.
Use this checklist for code reviews and migration plans. Mark each item pass, fail, or not applicable; for each failure, cite the reference file and severity.
UserDefaults, plists, source, logs, files, or
archives.SecItem* call checks OSStatus and handles common recoverable errors.SecAccessControl, not a
standalone Bool from LAContext.evaluatePolicy().kSecClass matches the item type and primary-key attributes.dataRepresentation, and designs for device-bound keys.SecTrust APIs, validates hostname/policy, and
uses SPKI or CA pinning when pinning is required.errSecItemNotFound handling.kSecAttrAccessibleWhenUnlocked implicitly by omitting the attribute.kSecAttrAccessibleAlways or
kSecAttrAccessibleAlwaysThisDeviceOnly, both deprecated.kSecAttrAccessible and kSecAttrAccessControl on the same add query.OSStatus handling and explicit accessibility in
examples.## Reference Files and
list the loaded references with a one-line purpose.kSecClass selection, primary keys, certificates, identities.SecAccessControl, background access, data protection.LAContext, enrollment-change handling.NSPinnedDomains, client certificates.© dpearson2699, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 15 other files (references) in skills/swift-security of dpearson2699/swift-ios-skills.
Open the folder on GitHubat commit 8d90fd1
Swift Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Swift Security this skilldpearson2699/swift-ios-skills | 1.2k | — | ~3.2k | Automated safety check: Pass | MIT | |
| Orca iOS Simulator Controlstablyai/orca | 87k | 1 repos | ~584 | Automated safety check: Pass | Apache-2.0 | |
| Apple Crash Log .NET Symbolicationdotnet/skills | 5.6k | 1 repos | ~2.4k | Automated safety check: Pass | MIT | |
| Swiftui Expert Skillomarshahine/HomeClaw | 176 | 4 repos | ~2.8k | Automated safety check: Pass | MIT | |
| Phoneagentrounak/PhoneAgent | 798 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Apple Designvrcm-team/VRCM | 179 | 1 repos | ~6.2k | Automated safety check: Pass | MIT |
stablyai/orca
iOS Simulator control from inside Orca, with the live device view in Orca's emulator pane. Use when driving a booted Apple Simulator on macOS: taps, gestures…
dotnet/skills
Resolves .NET runtime frames in Apple .ips crash logs to function names, source files and line numbers using dSYM symbols, atos and the Microsoft symbol server.
omarshahine/HomeClaw
A skill your agent uses when writing, reviewing, or refactoring SwiftUI code for iOS or macOS, including state management, view composition, performance, Liquid Glass adoption, or Instruments .trace…
rounak/PhoneAgent
Control a connected iPhone, iOS simulator, Android emulator, or Android device from macOS through PhoneAgent's JSON-RPC bridge.
vrcm-team/VRCM
Cross-platform UI/UX design reviewer grounded in Apple's Human Interface Guidelines (122 pages pulled from developer.apple.com, including 57 component pages) plus a design-craft lens for…
raintree-technology/hig-doctor
Create or update a shared Apple design context document that other HIG skills use to tailor guidance.
dpearson2699/swift-ios-skills
A skill your agent uses when capturing or analyzing an iOS .memgraph, especially when the task mentions a memory leak, heap growth, persistent memory increase, ownership path, or matched-capture…
dpearson2699/swift-ios-skills
Tokenize, tag, and analyze natural language text using Apple's NaturalLanguage framework and translate between languages with the Translation framework.
dpearson2699/swift-ios-skills
A skill your agent uses when capturing or analyzing ETTrace profiles for a focused iOS launch or runtime flow, including exact-build dSYM UUID matching, Simulator or device capture, processed…
dpearson2699/swift-ios-skills
Discover and configure Bluetooth and Wi-Fi accessories using AccessorySetupKit.
dpearson2699/swift-ios-skills
Implement, review, or improve Live Activities and Dynamic Island experiences in iOS apps using ActivityKit.
dpearson2699/swift-ios-skills
Measure ad effectiveness with privacy-preserving attribution using AdAttributionKit.
Categories
A skill your agent uses when working with iOS/macOS Keychain Services (SecItem queries, kSecClass, OSStatus errors), biometric authentication (LAContext, Face ID, Touch ID), CryptoKit (AES-GCM…. Swift Security is an agent skill from dpearson2699/swift-ios-skills. Use when working with iOS/macOS Keychain Services (SecItem queries, kSecClass, OSStatus errors), biometric authentication (LAContext, Face ID, Touch ID), CryptoKit (AES-GCM, ChaChaPoly, ECDSA, ECDH, HPKE, ML-KEM), Secure Enclave, secure credential storage (OAuth tokens, API keys), certificate pinning (SecTrust, SPKI), keychain sharing across apps/extensions, migrating secrets from UserDefaults or plists, or OWASP MASVS/MASTG mobile compliance on Apple platforms.
Swift Security fits situations like: working with iOS/macOS Keychain Services (SecItem queries; OSStatus errors); biometric authentication (LAContext; cryptoKit (AES-GCM.
Run `npx skills add dpearson2699/swift-ios-skills --skill swift-security -a claude-code`. Or copy the skill folder (skills/swift-security in dpearson2699/swift-ios-skills) into .claude/skills/swift-security in your project. Claude Code loads it when a task matches its description.
Run `npx skills add dpearson2699/swift-ios-skills --skill swift-security -a codex`. Or copy the skill folder (skills/swift-security in dpearson2699/swift-ios-skills) into .agents/skills/swift-security in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dpearson2699/swift-ios-skills --skill swift-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/swift-security, .gemini/skills/swift-security, .github/skills/swift-security and .opencode/skills/swift-security in your project.
SKILL.md names no scripts, command-line tools or credentials: Swift Security is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Swift Security is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 120k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Swift Security: Orca iOS Simulator Control (stablyai/orca, 87k stars), Apple Crash Log .NET Symbolication (dotnet/skills, 5.6k stars), Swiftui Expert Skill (omarshahine/HomeClaw, 176 stars) and Phoneagent (rounak/PhoneAgent, 798 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
dpearson2699 (a GitHub user) maintains it in dpearson2699/swift-ios-skills, which has 1,175 GitHub stars. The repository holds 86 skills in this directory. The repository was last updated on July 31, 2026.
Source: dpearson2699/swift-ios-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.