Analyzing macOS Binaries
trilwu/secskills
Reverse engineer and security-review macOS applications and Mach-O binaries — thinning universal binaries, recovering Objective-C/Swift structure, reading code-signing entitlements and the hardened…
Agent skill
by jeremylongshore in jeremylongshore/tons-of-skills-marketplace
Apply security best practices for Apple Notes automation scripts.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill apple-notes-security-basics -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace apple-notes-security-basics --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/apple-notes-security-basics .claude/skills/apple-notes-security-basics && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "apple-notes-security-basics" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/apple-notes-security-basics into .claude/skills/apple-notes-security-basics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "apple-notes-security-basics", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/apple-notes-security-basicsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill apple-notes-security-basics -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace apple-notes-security-basics --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/.curated/apple-notes-security-basics .agents/skills/apple-notes-security-basics && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "apple-notes-security-basics" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/apple-notes-security-basics into .agents/skills/apple-notes-security-basics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "apple-notes-security-basics", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill apple-notes-security-basics -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace apple-notes-security-basics --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/.curated/apple-notes-security-basics .cursor/skills/apple-notes-security-basics && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "apple-notes-security-basics" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/apple-notes-security-basics into .cursor/skills/apple-notes-security-basics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "apple-notes-security-basics", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/jeremylongshore/tons-of-skills-marketplace.git --path skills/.curated/apple-notes-security-basics--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill apple-notes-security-basics -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace apple-notes-security-basics --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/.curated/apple-notes-security-basics .gemini/skills/apple-notes-security-basics && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "apple-notes-security-basics" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/apple-notes-security-basics into .gemini/skills/apple-notes-security-basics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "apple-notes-security-basics", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install jeremylongshore/tons-of-skills-marketplace apple-notes-security-basicsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill apple-notes-security-basics -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/.curated/apple-notes-security-basics .github/skills/apple-notes-security-basics && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "apple-notes-security-basics" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/apple-notes-security-basics into .github/skills/apple-notes-security-basics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "apple-notes-security-basics", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill apple-notes-security-basics -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace apple-notes-security-basics --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/.curated/apple-notes-security-basics .opencode/skills/apple-notes-security-basics && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "apple-notes-security-basics" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/apple-notes-security-basics into .opencode/skills/apple-notes-security-basics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "apple-notes-security-basics", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
apple-notes-security-basicsApply security best practices for Apple Notes automation scripts.
Apple Notes Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Apply security best practices for Apple Notes automation scripts. Trigger: "apple notes security".
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Designed for Claude Code
It works with macOS. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadWriteEditBash(osascript:*)GrepFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
osascriptFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
developer.apple.comsupport.apple.comrainforestqa.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Designed for Claude Code
From compatibility in the SKILL.md frontmatter.
Apple Notes Security Basics loads about 1.5k tokens when it runs. Until then it costs about 32 tokens; SKILL.md has 493 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 493 words, ~1,541 tokens.
.claude/skills/apple-notes-security-basics/SKILL.md (or your agent's skills folder).Apple Notes security involves three layers: macOS TCC (Transparency, Consent, and Control) which gates which apps can send Apple Events to Notes.app, the macOS sandbox that prevents direct database access, and iCloud encryption that protects notes in transit and at rest. For automation scripts, the primary security concerns are: preventing unauthorized Apple Events access, securing exported note data, avoiding credential leakage in scripts, and understanding the difference between standard and end-to-end encrypted (locked) notes.
chmod 600)trap on exit)# View which apps have automation access in System Settings:
# System Settings > Privacy & Security > Automation
open "x-apple.systempreferences:com.apple.preference.security?Privacy_Automation"#!/bin/bash
# Secure export with cleanup on exit
EXPORT_FILE=$(mktemp /tmp/notes-export-XXXXXX.json)
trap 'rm -f "$EXPORT_FILE"' EXIT
# Export with restricted permissions from the start
umask 077
osascript -l JavaScript -e '
const Notes = Application("Notes");
JSON.stringify(Notes.defaultAccount.notes().map(n => ({
title: n.name(),
body: n.plaintext(),
folder: n.container().name()
})));
' > "$EXPORT_FILE"
echo "Exported to $EXPORT_FILE ($(wc -c < "$EXPORT_FILE") bytes)"
# Process the file...
# File is automatically deleted on exit via trap// Locked notes (end-to-end encrypted) cannot be read via JXA
// Attempting to access a locked note's body() returns an error
const Notes = Application("Notes");
const allNotes = Notes.defaultAccount.notes();
allNotes.forEach(n => {
try {
const body = n.body();
// Note is unlocked — process normally
} catch (e) {
// Note is likely locked (encrypted)
console.log(`Skipping locked note: ${n.name()}`);
}
});
// Note: There is no JXA API to unlock notes programmatically.
// Locked notes require the user's password/biometrics in Notes.app UI.# Store automation credentials in macOS Keychain (not in script files)
# Add a credential interactively; do not place a secret in command-line history.
security add-generic-password -a "notes-automation" -s "notes-export-key" \
-T /usr/bin/osascript
# Retrieve in scripts
KEY=$(security find-generic-password -a "notes-automation" -s "notes-export-key" -w 2>/dev/null)
[ -z "$KEY" ] && echo "ERROR: Keychain credential not found" && exit 1| Issue | Cause | Solution |
|---|---|---|
| TCC prompt never appears | App already denied; macOS won't re-prompt | tccutil reset AppleEvents; retry |
| Cannot read locked notes | End-to-end encrypted; no JXA access | Skip locked notes; document limitation for users |
| Export file readable by other users | Default umask too permissive | Set umask 077 before writing; chmod 600 after |
| Script exposes note content in process list | Note content passed as CLI argument | Pipe content via stdin or temp file instead of -e argument |
| Automation works after upgrade but TCC reset | macOS upgrade clears some TCC entries | Re-approve automation permissions after every OS update |
The security review produces a permission inventory, export-protection decision, and redacted evidence that locked notes were skipped. It must not include TCC database rows, Keychain secrets, note bodies, or raw note titles.
After an operating-system upgrade, open the Automation privacy pane, review the exact client entry, and run a read-only scoped smoke test. If access is no longer approved, stop the job and request consent through the documented owner; do not reset system-wide permissions to force a prompt.
For enterprise access control and MDM integration, see apple-notes-enterprise-rbac. For production security validation, see apple-notes-prod-checklist.
© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/.curated/apple-notes-security-basics of jeremylongshore/tons-of-skills-marketplace.
Open the folder on GitHubat commit cfae287
Apple Notes Security Basics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Apple Notes Security Basics this skilljeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~1.5k | Automated safety check: Pass | MIT | |
| Analyzing macOS Binariestrilwu/secskills | 157 | — | ~1.7k | Automated safety check: Pass | MIT | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 4 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Site ArchitectureAvdLee/RocketSimApp | 805 | 11 repos | ~3.3k | Automated safety check: Pass | Custom licence | |
| Engine Whats Newflutter/flutter | 179k | — | ~978 | Automated safety check: Pass | BSD-3-Clause | |
| macOS Spm App PackagingDimillian/Skills | 4k | 5 repos | ~1.2k | Automated safety check: Pass | MIT |
trilwu/secskills
Reverse engineer and security-review macOS applications and Mach-O binaries — thinning universal binaries, recovering Objective-C/Swift structure, reading code-signing entitlements and the hardened…
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
AvdLee/RocketSimApp
When the user wants to plan, map, or restructure their website's page hierarchy, navigation, URL structure, or internal linking.
flutter/flutter
Generates the "what's new" release summary and diff file for changes in the Flutter engine (//engine/src/flutter) between two releases (e.g., 3.47 vs 3.44).
Dimillian/Skills
Scaffold, build, and package SwiftPM-based macOS apps without an Xcode project.
openclaw/openclaw
Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.
jeremylongshore/tons-of-skills-marketplace
Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.
jeremylongshore/tons-of-skills-marketplace
Execute proactive auto-loading: automatically detects and loads agents.md files.
jeremylongshore/tons-of-skills-marketplace
Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.
jeremylongshore/tons-of-skills-marketplace
Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.
Works with
Apply security best practices for Apple Notes automation scripts. Apple Notes Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Apply security best practices for Apple Notes automation scripts.
Apple Notes Security Basics fits situations like: tasks that involve Security review.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill apple-notes-security-basics -a claude-code`. Or copy the skill folder (skills/.curated/apple-notes-security-basics in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/apple-notes-security-basics in your project. Claude Code loads it when a task matches its description.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill apple-notes-security-basics -a codex`. Or copy the skill folder (skills/.curated/apple-notes-security-basics in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/apple-notes-security-basics in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill apple-notes-security-basics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/apple-notes-security-basics, .gemini/skills/apple-notes-security-basics, .github/skills/apple-notes-security-basics and .opencode/skills/apple-notes-security-basics in your project.
Going by SKILL.md and its folder, Apple Notes Security Basics needs the command-line tools its instructions call (osascript). Its frontmatter pre-approves these tools: Read, Write, Edit, Bash(osascript:*), Grep. Compatibility (from SKILL.md): Designed for Claude Code.
SKILL.md names 3 domains. As links in the text: developer.apple.com, support.apple.com and rainforestqa.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Apple Notes Security Basics is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 6.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Apple Notes Security Basics: Analyzing macOS Binaries (trilwu/secskills, 157 stars), Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Site Architecture (AvdLee/RocketSimApp, 805 stars) and Engine Whats New (flutter/flutter, 179k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.
Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.