Agent skill

Hunt macOS

by Encod3d-Sec in Encod3d-Sec/TORCH

macOS attack hunting - foothold to root/persistence on a macOS host.

MITAuto-check passedMobile

Install Hunt macOS

skills CLI
$ npx skills add Encod3d-Sec/TORCH --skill hunt-macos -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Encod3d-Sec/TORCH hunt-macos --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt/hunt-macos .claude/skills/hunt-macos && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hunt-macos
GitHub stars
329
Token cost
~1.9k tokens
SKILL.md length
815 words
Files
1
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

macOS attack hunting - foothold to root/persistence on a macOS host.

  • Works in 5 steps: Enumerate the foothold first -… → Credential / secret loot -… → Evasion / bypass the OS security stack… → …
  • Tasks that involve App store release
  • SKILL.md covers Wiki, Environment note, Attack surface signals and Methodology, plus 2 more sections
  • Calls sqlite3 and python3

What it does

Hunt macOS is an agent skill from Encod3d-Sec/TORCH. macOS attack hunting - foothold to root/persistence on a macOS host. TCC/Gatekeeper/SIP bypass, keychain + credential loot, code-signing/entitlements abuse, XPC/dylib/library injection, launch-constraint evasion, MDM/installer abuse. Wiki-first, FIND schema output.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Mobile, covering App store release. It works with macOS. The repository describes itself as: Karpathy LLM based claude harness for PenetrationTesting / Bugbounty using obsidian. The licence is MIT.

When your agent uses it

  • Tasks that involve App store release

Example prompts

  • “Use the hunt-macos skill to maco attack hunting - foothold to root/persistence on a macOS host”
  • “/hunt-macos”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Enumerate the foothold first - Skill(arsenal) then [[macos-enumeration]]: users, running
  2. Credential / secret loot - [[macos-keychain]] (login keychain dump, security CLI, keychain
  3. Evasion / bypass the OS security stack (pick per what's actually gating you)
  4. Privilege escalation / sandbox escape - [[macos-privesc]] (the general checklist: SUID, sudo,
  5. Persistence + lateral - [[macos-persistence]] (launch agents/daemons, login items, cron) and

What it can do on your machine

Read from SKILL.md and the folder at commit d21b6c9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • sqlite3
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hunt macOS loads about 1.9k tokens when it runs. Until then it costs about 69 tokens; SKILL.md has 815 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~69
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Encod3d-Sec/TORCH at commit d21b6c9, republished under its MIT licence (© Encod3d-Sec). 815 words, ~1,923 tokens.

Download SKILL.mdSave it as .claude/skills/hunt-macos/SKILL.md (or your agent's skills folder).
name
hunt-macos
description
macOS attack hunting - foothold to root/persistence on a macOS host. TCC/Gatekeeper/SIP bypass, keychain + credential loot, code-signing/entitlements abuse, XPC/dylib/library injection, launch-constraint evasion, MDM/installer abuse. Wiki-first, FIND schema output.

Hunt: macOS

Assumes hunt-core for the scope gate, two-account rule, confirmation gate, enumeration limits, stop conditions, wiki protocol, FIND output, and Deadends. Do not re-derive any of that here.

Wiki

qmd_query "macOS TCC SIP Gatekeeper AMFI keychain XPC dylib injection sandbox escape code signing entitlements" via wiki-search MCP

Hub: [[macos-moc]] (live index). Primary page: [[macos-tcc]]. Payload arsenal: wiki/payloads/macos-app-injection.md. Anchors: [[macos-privesc]] (general privesc checklist), [[macos-keychain]] (credential/DB harvest).

Environment note

macOS boxes on THM/HTB are usually a VM (not real Apple hardware) - SIP/Gatekeeper/TCC still apply as shipped, but device-specific protections (Secure Enclave, T2) generally do not. Confirm root/admin vs a sandboxed app context before picking an escalation path - the sandbox-escape and TCC-bypass techniques below assume different starting points.

Attack surface signals

Detected via: SSH/service banner (Darwin, Mac OS X 10., macOS 1[1-5]), a .app bundle / .plist delivered as a foothold vector, Bonjour/mDNS (5353), ARD/screen-sharing (5900/3283), SMB served by smbd with a macOS-flavoured share layout, or a CTF prompt naming macOS/Darwin explicitly. Footholds: a delivered .pkg/.dmg/.app (installer/Gatekeeper abuse), a web app or service running as a low-priv user, physical/VNC/screen-sharing access to a logged-in session.

Rank the surface once you have a foothold:

  • TCC / SIP / Gatekeeper / AMFI - the macOS-specific security stack; a bypass here is the signature finding of this class and the primary path to protected data or unsigned code exec.
  • Keychain / credential loot - highest reward-per-effort; a login-keychain dump or a reused hash often beats grinding a hardened control (see chaining note).
  • XPC / dylib / library injection - inherit a privileged or entitled process's rights; the main local-privesc lever once enumeration finds a vulnerable service or a hijackable load path.
  • Sandbox escape - only relevant from a sandboxed app context; escapes to the full user context.
  • MDM / installer abuse - a .pkg postinstall runs as root at install time; MDM enrollment reaches the whole fleet. Highest blast radius when either is present.

Methodology

  1. Enumerate the foothold first - Skill(arsenal) then [[macos-enumeration]]: users, running processes/services (launchd agents/daemons), installed .app bundles, network map, SIP status (csrutil status), Gatekeeper status (spctl --status), TCC database location + entries.
bash
csrutil status                          # SIP enabled/disabled - gates which privesc paths are live
spctl --status                          # Gatekeeper assessment on/off
sqlite3 ~/Library/Application\ Support/com.apple.TCC/TCC.db "select * from access"   # per-app TCC grants
  1. Credential / secret loot - [[macos-keychain]] (login keychain dump, security CLI, keychain ACL bypass) then the wider sweep in [[macos-loot-locations]] (local password hashes under /var/db/dslocal/, browser/app credential stores, sensitive DBs) - crack recovered hashes with hashcat -m 7100 (salted SHA512-PBKDF2).
  2. Evasion / bypass the OS security stack (pick per what's actually gating you):
    • [[macos-gatekeeper]] - quarantine-attribute stripping, unsigned/ad-hoc-signed app execution.
    • [[macos-code-signing]] - signature/entitlement inspection and abuse (codesign, ad-hoc re-signing).
    • [[macos-amfi]] - AppleMobileFileIntegrity internals underlying code-signing enforcement, and its bypasses.
    • [[macos-launch-constraints]] - trust-cache / launch-constraint evasion on newer macOS.
    • [[macos-dirty-nib]] - NIB-file injection into a signed app to gain its entitlements.
  3. Privilege escalation / sandbox escape - [[macos-privesc]] (the general checklist: SUID, sudo, cron/launchd, writable app bundles) alongside:
    • [[macos-sandbox-escape]] - escape an app sandbox profile to the full user context.
    • [[macos-xpc-abuse]] - abuse a privileged XPC service's exposed Mach interface.
    • [[macos-function-hooking]] / [[macos-library-injection]] / [[macos-thread-injection]] / [[macos-app-injection]] (payload) - DYLD_INSERT_LIBRARIES/dylib hijack/thread-injection into a privileged or entitled process to inherit its rights.
    • [[macos-authorization-db]] - Authorization Services rights-database manipulation for a privesc.
    • [[macos-tcc]] - TCC bypass to reach protected data (contacts/photos/full-disk-access/camera) or ride a TCC-granted app's entitlement.
    • [[macos-installers-abuse]] - .pkg postinstall-script / .dmg abuse for root-run code at install time.
    • [[macos-chromium-injection]] - inject into a Chromium-based app (Electron/Chrome) via its debug/CEF surface for code exec in that app's context.
  4. Persistence + lateral - [[macos-persistence]] (launch agents/daemons, login items, cron) and [[macos-mdm]] (enrolled-MDM abuse for fleet-wide reach, if the host is MDM-managed).
Show full SKILL.md (280 more words)Show less

Chaining. Foothold -> keychain/credential loot -> privesc is the reliable macOS chain: a low-priv shell first dumps the login keychain and /var/db/dslocal/ hashes ([[macos-keychain]] / [[macos-loot-locations]]), a cracked or reused admin password then unlocks sudo/security and the privileged XPC/dylib paths in step 4. Loot before you grind a hardened control.

Evasion. Prefer the least-noisy path that clears the gate: strip the com.apple.quarantine xattr rather than fully re-sign, ride an already-TCC-granted app's entitlement rather than defeating TCC head-on, and load via a hijackable dylib search path before touching AMFI/launch-constraint internals. Escalate to heavier bypasses ([[macos-amfi]], [[macos-launch-constraints]]) only when the lighter path is actually blocked.

Distill a confirmed reusable macOS technique per hunt-core: python3 scripts/wiki-stage.py --kind technique --slug <slug> --target-page techniques/macos/macos-privesc.md.

Confirmation gate

NOT confirmation: a permissive entitlement (com.apple.security.*, a get-task-allow or a private-framework entitlement) present in a plist; an unsigned or ad-hoc-signed binary sitting on disk; a world-writable app bundle or launchd plist; csrutil/spctl reporting a control as present; a DYLD_INSERT_LIBRARIES that the loader ignored on a hardened process. A capability that exists is not a control that was bypassed.

IS confirmation: the control was actually defeated and demonstrated - TCC bypassed and the protected resource (contacts/photos/full-disk/camera) actually read; SIP-protected path written or csrutil-guarded action performed; Gatekeeper/AMFI/launch-constraint bypassed and your unsigned code ran past it; an injected dylib/thread executing inside the privileged/entitled process and exercising its rights; a .pkg postinstall or XPC call yielding a root-context action you performed - each re-verified in a clean session and reproduced from your own written steps.

Severity

SeverityClass
CRITICALroot / SIP-disabled code exec, MDM fleet compromise
HIGHsandbox escape, XPC privesc, keychain-wide credential dump
MEDIUMTCC bypass to a single data class, Gatekeeper bypass with no privilege gain

© Encod3d-Sec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/hunt/hunt-macos of Encod3d-Sec/TORCH.

Open the folder on GitHubat commit d21b6c9

Compare with similar skills

Hunt macOS next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hunt macOS compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hunt macOS this skillEncod3d-Sec/TORCH329—~1.9kAutomated safety check: PassMIT
Workbuddy Skin Studiocdredfox/workbuddy-skin-studio198—~1.5kAutomated safety check: PassMIT
Store Screenshotspandulapeter/campfire101—~3kAutomated safety check: PassMPL-2.0
macOS Signing Entitlementsrobinebers/openusage4.3k—~445Automated safety check: PassMIT
Signing Entitlementsrobinebers/openusage4.3k—~468Automated safety check: PassMIT
iOS Accessibilitydpearson2699/swift-ios-skills1.2k—~4.6kAutomated safety check: PassCustom licence

Similar skills

  • Workbuddy Skin Studio

    cdredfox/workbuddy-skin-studio

    Apply a reversible theme/skin to the WorkBuddy desktop app (Tencent AI office agent) via local Chromium DevTools Protocol (CDP) injection.

    198 GitHub stars~1.5k tokensUpdated 2 mo ago
    MobileAuto-check passed
  • Store Screenshots

    pandulapeter/campfire

    Retake Campfire's promotional images for every platform and form factor — the store listings (Play Store, App Store, Mac App Store, Microsoft Store), the Play Store feature graphic, Apple's product…

    101 GitHub stars~3k tokensUpdated today
    MobileAuto-check passed
  • macOS Signing Entitlements

    robinebers/openusage

    Inspect macOS signing, entitlements, and Gatekeeper issues. An agent skill from robinebers/openusage.

    4.3k GitHub stars~445 tokensUpdated 3 days ago
    MobileAuto-check passed
  • Signing Entitlements

    robinebers/openusage

    Inspect signing, entitlements, hardened runtime, and Gatekeeper issues for macOS apps.

    4.3k GitHub stars~468 tokensUpdated 3 days ago
    MobileAuto-check passed
  • iOS Accessibility

    dpearson2699/swift-ios-skills

    Build and audit SwiftUI, UIKit, and AppKit accessibility for VoiceOver, Voice Control, Switch Control, Full Keyboard Access, Dynamic Type, focus restoration, labels/traits/actions, traversal, custom…

    1.2k GitHub stars~4.6k tokensUpdated 2 mo ago
    MobileAuto-check passed
  • Review Prompt

    gustavscirulis/snapgrid

    Generates smart App Store review prompt infrastructure with configurable conditions and platform detection.

    117 GitHub starsUsed in 1 repo~1.3k tokens
    MobileAuto-check: notes

More from Encod3d-Sec/TORCH

All 35 skills in this repo
  • Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.

    329 GitHub stars~611 tokensUpdated 1 mo ago
    Auto-check passed
  • Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.

    329 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • CTF Campaign Driver

    Encod3d-Sec/TORCH

    Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely.

    329 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check: notes
  • Adaptive Web Fuzzing

    Encod3d-Sec/TORCH

    Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.

    329 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Hunt macOS

What does Hunt macOS do?

macOS attack hunting - foothold to root/persistence on a macOS host. Hunt macOS is an agent skill from Encod3d-Sec/TORCH. macOS attack hunting - foothold to root/persistence on a macOS host.

When should I use Hunt macOS?

Hunt macOS fits situations like: tasks that involve App store release.

How do I install Hunt macOS in Claude Code?

Run `npx skills add Encod3d-Sec/TORCH --skill hunt-macos -a claude-code`. Or copy the skill folder (skills/hunt/hunt-macos in Encod3d-Sec/TORCH) into .claude/skills/hunt-macos in your project. Claude Code loads it when a task matches its description.

How do I install Hunt macOS in Codex?

Run `npx skills add Encod3d-Sec/TORCH --skill hunt-macos -a codex`. Or copy the skill folder (skills/hunt/hunt-macos in Encod3d-Sec/TORCH) into .agents/skills/hunt-macos in your project. Codex loads it when a task matches its description.

Can I use Hunt macOS in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Encod3d-Sec/TORCH --skill hunt-macos -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-macos, .gemini/skills/hunt-macos, .github/skills/hunt-macos and .opencode/skills/hunt-macos in your project.

What does Hunt macOS need to run?

Going by SKILL.md and its folder, Hunt macOS needs the command-line tools its instructions call (sqlite3 and python3). Our summary lists: Python 3.

Does Hunt macOS access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hunt macOS safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hunt macOS use?

Hunt macOS is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hunt macOS use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hunt macOS?

Skills that share tags, products or a category with Hunt macOS: Workbuddy Skin Studio (cdredfox/workbuddy-skin-studio, 198 stars), Store Screenshots (pandulapeter/campfire, 101 stars), macOS Signing Entitlements (robinebers/openusage, 4.3k stars) and Signing Entitlements (robinebers/openusage, 4.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hunt macOS?

Encod3d-Sec (a GitHub user) maintains it in Encod3d-Sec/TORCH, which has 329 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 1, 2026.

Source: Encod3d-Sec/TORCH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.