Workbuddy Skin Studio
cdredfox/workbuddy-skin-studio
Apply a reversible theme/skin to the WorkBuddy desktop app (Tencent AI office agent) via local Chromium DevTools Protocol (CDP) injection.
macOS attack hunting - foothold to root/persistence on a macOS host.
$ npx skills add Encod3d-Sec/TORCH --skill hunt-macos -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Encod3d-Sec/TORCH hunt-macos --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt/hunt-macos .claude/skills/hunt-macos && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "hunt-macos" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/hunt/hunt-macos into .claude/skills/hunt-macos/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-macos", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Encod3d-Sec/TORCH/tree/main/skills/hunt/hunt-macosType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Encod3d-Sec/TORCH --skill hunt-macos -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Encod3d-Sec/TORCH hunt-macos --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/hunt/hunt-macos .agents/skills/hunt-macos && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "hunt-macos" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/hunt/hunt-macos into .agents/skills/hunt-macos/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-macos", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Encod3d-Sec/TORCH --skill hunt-macos -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Encod3d-Sec/TORCH hunt-macos --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/hunt/hunt-macos .cursor/skills/hunt-macos && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "hunt-macos" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/hunt/hunt-macos into .cursor/skills/hunt-macos/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-macos", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Encod3d-Sec/TORCH.git --path skills/hunt/hunt-macos--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Encod3d-Sec/TORCH --skill hunt-macos -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Encod3d-Sec/TORCH hunt-macos --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/hunt/hunt-macos .gemini/skills/hunt-macos && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "hunt-macos" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/hunt/hunt-macos into .gemini/skills/hunt-macos/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-macos", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Encod3d-Sec/TORCH hunt-macosInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Encod3d-Sec/TORCH --skill hunt-macos -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/hunt/hunt-macos .github/skills/hunt-macos && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "hunt-macos" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/hunt/hunt-macos into .github/skills/hunt-macos/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-macos", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Encod3d-Sec/TORCH --skill hunt-macos -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Encod3d-Sec/TORCH hunt-macos --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/hunt/hunt-macos .opencode/skills/hunt-macos && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "hunt-macos" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/hunt/hunt-macos into .opencode/skills/hunt-macos/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-macos", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
hunt-macosmacOS attack hunting - foothold to root/persistence on a macOS host.
Hunt macOS is an agent skill from Encod3d-Sec/TORCH. macOS attack hunting - foothold to root/persistence on a macOS host. TCC/Gatekeeper/SIP bypass, keychain + credential loot, code-signing/entitlements abuse, XPC/dylib/library injection, launch-constraint evasion, MDM/installer abuse. Wiki-first, FIND schema output.
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Mobile, covering App store release. It works with macOS. The repository describes itself as: Karpathy LLM based claude harness for PenetrationTesting / Bugbounty using obsidian. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit d21b6c9. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
sqlite3python3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Hunt macOS loads about 1.9k tokens when it runs. Until then it costs about 69 tokens; SKILL.md has 815 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Encod3d-Sec/TORCH at commit d21b6c9, republished under its MIT licence (© Encod3d-Sec). 815 words, ~1,923 tokens.
.claude/skills/hunt-macos/SKILL.md (or your agent's skills folder).Assumes hunt-core for the scope gate, two-account rule, confirmation gate, enumeration limits, stop conditions, wiki protocol, FIND output, and Deadends. Do not re-derive any of that here.
qmd_query "macOS TCC SIP Gatekeeper AMFI keychain XPC dylib injection sandbox escape code signing entitlements" via wiki-search MCPHub: [[macos-moc]] (live index). Primary page: [[macos-tcc]]. Payload arsenal: wiki/payloads/macos-app-injection.md.
Anchors: [[macos-privesc]] (general privesc checklist), [[macos-keychain]] (credential/DB harvest).
macOS boxes on THM/HTB are usually a VM (not real Apple hardware) - SIP/Gatekeeper/TCC still apply as shipped, but device-specific protections (Secure Enclave, T2) generally do not. Confirm root/admin vs a sandboxed app context before picking an escalation path - the sandbox-escape and TCC-bypass techniques below assume different starting points.
Detected via: SSH/service banner (Darwin, Mac OS X 10., macOS 1[1-5]), a .app bundle / .plist
delivered as a foothold vector, Bonjour/mDNS (5353), ARD/screen-sharing (5900/3283), SMB served by
smbd with a macOS-flavoured share layout, or a CTF prompt naming macOS/Darwin explicitly.
Footholds: a delivered .pkg/.dmg/.app (installer/Gatekeeper abuse), a web app or service running
as a low-priv user, physical/VNC/screen-sharing access to a logged-in session.
Rank the surface once you have a foothold:
.pkg postinstall runs as root at install time; MDM enrollment reaches
the whole fleet. Highest blast radius when either is present.Skill(arsenal) then [[macos-enumeration]]: users, running
processes/services (launchd agents/daemons), installed .app bundles, network map, SIP status
(csrutil status), Gatekeeper status (spctl --status), TCC database location + entries.csrutil status # SIP enabled/disabled - gates which privesc paths are live
spctl --status # Gatekeeper assessment on/off
sqlite3 ~/Library/Application\ Support/com.apple.TCC/TCC.db "select * from access" # per-app TCC grantssecurity CLI, keychain
ACL bypass) then the wider sweep in [[macos-loot-locations]] (local password hashes under
/var/db/dslocal/, browser/app credential stores, sensitive DBs) - crack recovered hashes with
hashcat -m 7100 (salted SHA512-PBKDF2).codesign, ad-hoc re-signing).DYLD_INSERT_LIBRARIES/dylib hijack/thread-injection into a
privileged or entitled process to inherit its rights..pkg postinstall-script / .dmg abuse for root-run code at install time.Chaining. Foothold -> keychain/credential loot -> privesc is the reliable macOS chain: a
low-priv shell first dumps the login keychain and /var/db/dslocal/ hashes ([[macos-keychain]] /
[[macos-loot-locations]]), a cracked or reused admin password then unlocks sudo/security and the
privileged XPC/dylib paths in step 4. Loot before you grind a hardened control.
Evasion. Prefer the least-noisy path that clears the gate: strip the com.apple.quarantine
xattr rather than fully re-sign, ride an already-TCC-granted app's entitlement rather than defeating
TCC head-on, and load via a hijackable dylib search path before touching AMFI/launch-constraint
internals. Escalate to heavier bypasses ([[macos-amfi]], [[macos-launch-constraints]]) only when the
lighter path is actually blocked.
Distill a confirmed reusable macOS technique per hunt-core: python3 scripts/wiki-stage.py --kind technique --slug <slug> --target-page techniques/macos/macos-privesc.md.
NOT confirmation: a permissive entitlement (com.apple.security.*, a get-task-allow or a
private-framework entitlement) present in a plist; an unsigned or ad-hoc-signed binary sitting on
disk; a world-writable app bundle or launchd plist; csrutil/spctl reporting a control as present;
a DYLD_INSERT_LIBRARIES that the loader ignored on a hardened process. A capability that exists
is not a control that was bypassed.
IS confirmation: the control was actually defeated and demonstrated - TCC bypassed and the
protected resource (contacts/photos/full-disk/camera) actually read; SIP-protected path written or
csrutil-guarded action performed; Gatekeeper/AMFI/launch-constraint bypassed and your unsigned code
ran past it; an injected dylib/thread executing inside the privileged/entitled process and
exercising its rights; a .pkg postinstall or XPC call yielding a root-context action you performed -
each re-verified in a clean session and reproduced from your own written steps.
| Severity | Class |
|---|---|
| CRITICAL | root / SIP-disabled code exec, MDM fleet compromise |
| HIGH | sandbox escape, XPC privesc, keychain-wide credential dump |
| MEDIUM | TCC bypass to a single data class, Gatekeeper bypass with no privilege gain |
© Encod3d-Sec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/hunt/hunt-macos of Encod3d-Sec/TORCH.
Open the folder on GitHubat commit d21b6c9
Hunt macOS next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Hunt macOS this skillEncod3d-Sec/TORCH | 329 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Workbuddy Skin Studiocdredfox/workbuddy-skin-studio | 198 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Store Screenshotspandulapeter/campfire | 101 | — | ~3k | Automated safety check: Pass | MPL-2.0 | |
| macOS Signing Entitlementsrobinebers/openusage | 4.3k | — | ~445 | Automated safety check: Pass | MIT | |
| Signing Entitlementsrobinebers/openusage | 4.3k | — | ~468 | Automated safety check: Pass | MIT | |
| iOS Accessibilitydpearson2699/swift-ios-skills | 1.2k | — | ~4.6k | Automated safety check: Pass | Custom licence |
cdredfox/workbuddy-skin-studio
Apply a reversible theme/skin to the WorkBuddy desktop app (Tencent AI office agent) via local Chromium DevTools Protocol (CDP) injection.
pandulapeter/campfire
Retake Campfire's promotional images for every platform and form factor — the store listings (Play Store, App Store, Mac App Store, Microsoft Store), the Play Store feature graphic, Apple's product…
robinebers/openusage
Inspect macOS signing, entitlements, and Gatekeeper issues. An agent skill from robinebers/openusage.
robinebers/openusage
Inspect signing, entitlements, hardened runtime, and Gatekeeper issues for macOS apps.
dpearson2699/swift-ios-skills
Build and audit SwiftUI, UIKit, and AppKit accessibility for VoiceOver, Voice Control, Switch Control, Full Keyboard Access, Dynamic Type, focus restoration, labels/traits/actions, traversal, custom…
gustavscirulis/snapgrid
Generates smart App Store review prompt infrastructure with configurable conditions and platform detection.
Encod3d-Sec/TORCH
Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.
Encod3d-Sec/TORCH
Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.
Encod3d-Sec/TORCH
Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.
Encod3d-Sec/TORCH
Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn.
Encod3d-Sec/TORCH
Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely.
Encod3d-Sec/TORCH
Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.
Works with
macOS attack hunting - foothold to root/persistence on a macOS host. Hunt macOS is an agent skill from Encod3d-Sec/TORCH. macOS attack hunting - foothold to root/persistence on a macOS host.
Hunt macOS fits situations like: tasks that involve App store release.
Run `npx skills add Encod3d-Sec/TORCH --skill hunt-macos -a claude-code`. Or copy the skill folder (skills/hunt/hunt-macos in Encod3d-Sec/TORCH) into .claude/skills/hunt-macos in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Encod3d-Sec/TORCH --skill hunt-macos -a codex`. Or copy the skill folder (skills/hunt/hunt-macos in Encod3d-Sec/TORCH) into .agents/skills/hunt-macos in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Encod3d-Sec/TORCH --skill hunt-macos -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-macos, .gemini/skills/hunt-macos, .github/skills/hunt-macos and .opencode/skills/hunt-macos in your project.
Going by SKILL.md and its folder, Hunt macOS needs the command-line tools its instructions call (sqlite3 and python3). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Hunt macOS is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Hunt macOS: Workbuddy Skin Studio (cdredfox/workbuddy-skin-studio, 198 stars), Store Screenshots (pandulapeter/campfire, 101 stars), macOS Signing Entitlements (robinebers/openusage, 4.3k stars) and Signing Entitlements (robinebers/openusage, 4.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Encod3d-Sec (a GitHub user) maintains it in Encod3d-Sec/TORCH, which has 329 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 1, 2026.
Source: Encod3d-Sec/TORCH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.