Agent skill

Signing Entitlements

by robinebers in robinebers/openusage

Inspect signing, entitlements, hardened runtime, and Gatekeeper issues for macOS apps.

MITAuto-check passedMobile

Install Signing Entitlements

skills CLI
$ npx skills add robinebers/openusage --skill signing-entitlements -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install robinebers/openusage signing-entitlements --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/robinebers/openusage.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/signing-entitlements .claude/skills/signing-entitlements && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
signing-entitlements
GitHub stars
4.3k
Token cost
~468 tokens
SKILL.md length
195 words
Files
1
Skills in repo
25
Repo updated
First seen
Licence
MIT

At a glance

Inspect signing, entitlements, hardened runtime, and Gatekeeper issues for macOS apps.

  • Works in 4 steps: Inspect the bundle or binary. → Read signing details. → Classify the failure. → …
  • Asked to diagnose code signing failures
  • SKILL.md covers Quick Start, Workflow, Useful Commands and Guardrails, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Signing Entitlements is an agent skill from robinebers/openusage. Inspect signing, entitlements, hardened runtime, and Gatekeeper issues for macOS apps. Use when asked to diagnose code signing failures, missing entitlements, sandbox problems, notarization prerequisites, or trust-policy launch errors.

Its SKILL.md is about 470 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Mobile, covering App store release. It works with macOS. The repository describes itself as: Burning through your subscriptions too fast? Paying for stuff you never use? Stop guessing. OpenUsage is free and open source. The licence is MIT.

When your agent uses it

  • Asked to diagnose code signing failures
  • Missing entitlements
  • Sandbox problems
  • Notarization prerequisites

Example prompts

  • “/signing-entitlements”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Inspect the bundle or binary.
  2. Read signing details.
  3. Classify the failure.
  4. Explain the minimum fix path.

What it can do on your machine

Read from SKILL.md and the folder at commit bb7de17. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Signing Entitlements loads about 468 tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 195 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~468

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from robinebers/openusage at commit bb7de17, republished under its MIT licence (© robinebers). 195 words, ~468 tokens.

Download SKILL.mdSave it as .claude/skills/signing-entitlements/SKILL.md (or your agent's skills folder).
name
signing-entitlements
description
Inspect signing, entitlements, hardened runtime, and Gatekeeper issues for macOS apps. Use when asked to diagnose code signing failures, missing entitlements, sandbox problems, notarization prerequisites, or trust-policy launch errors.

Signing & Entitlements

Quick Start

Use this skill when the failure smells like codesigning rather than compilation: launch refusal, missing entitlement, invalid signature, sandbox mismatch, hardened runtime confusion, or trust-policy rejection.

Workflow

  1. Inspect the bundle or binary.

    • Locate the .app or executable.
    • Identify the main binary inside Contents/MacOS/.
  2. Read signing details.

    • Use codesign -dvvv --entitlements :- <path>.
    • Use spctl -a -vv <path> when Gatekeeper behavior matters.
    • Use plutil -p for entitlements or Info.plist inspection.
  3. Classify the failure.

    • Unsigned or ad hoc signed
    • Wrong identity
    • Entitlement mismatch
    • Hardened runtime issue
    • App Sandbox issue
    • Nested code signing issue
    • Distribution/notarization prerequisite issue
  4. Explain the minimum fix path.

    • Say exactly what is wrong.
    • Show the shortest set of validation or repair commands.
    • Distinguish local development problems from distribution problems.

Useful Commands

  • codesign -dvvv --entitlements :- <app-or-binary>
  • spctl -a -vv <app-or-binary>
  • security find-identity -p codesigning -v
  • plutil -p <path-to-entitlements-or-plist>

Guardrails

  • Never invent missing entitlements.
  • Do not conflate notarization with local debug signing.
  • If the real issue is a build setting or provisioning profile, say so directly.

Output Expectations

Provide:

  • what artifact was inspected
  • what signing state it is in
  • the exact failure class
  • the minimum fix or validation sequence

© robinebers, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/signing-entitlements of robinebers/openusage.

Open the folder on GitHubat commit bb7de17

Compare with similar skills

Signing Entitlements next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Signing Entitlements compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Signing Entitlements this skillrobinebers/openusage4.3k—~468Automated safety check: PassMIT
Workbuddy Skin Studiocdredfox/workbuddy-skin-studio197—~1.5kAutomated safety check: PassMIT
Store Screenshotspandulapeter/campfire101—~3.1kAutomated safety check: PassMPL-2.0
iOS Accessibilitydpearson2699/swift-ios-skills1.2k—~4.6kAutomated safety check: PassCustom licence
Hunt macOSEncod3d-Sec/TORCH329—~1.9kAutomated safety check: PassMIT
Review Promptgustavscirulis/snapgrid1161 repos~1.3kAutomated safety check: NotesCustom licence

Similar skills

  • Workbuddy Skin Studio

    cdredfox/workbuddy-skin-studio

    Apply a reversible theme/skin to the WorkBuddy desktop app (Tencent AI office agent) via local Chromium DevTools Protocol (CDP) injection.

    197 GitHub stars~1.5k tokensUpdated 2 mo ago
    MobileAuto-check passed
  • Store Screenshots

    pandulapeter/campfire

    Retake Campfire's promotional images for every platform and form factor — the store listings (Play Store, App Store, Mac App Store, Microsoft Store), the Play Store feature graphic, Apple's product…

    101 GitHub stars~3.1k tokensUpdated today
    MobileAuto-check passed
  • iOS Accessibility

    dpearson2699/swift-ios-skills

    Build and audit SwiftUI, UIKit, and AppKit accessibility for VoiceOver, Voice Control, Switch Control, Full Keyboard Access, Dynamic Type, focus restoration, labels/traits/actions, traversal, custom…

    1.2k GitHub stars~4.6k tokensUpdated 2 mo ago
    MobileAuto-check passed
  • Hunt macOS

    Encod3d-Sec/TORCH

    macOS attack hunting - foothold to root/persistence on a macOS host.

    329 GitHub stars~1.9k tokensUpdated 1 mo ago
    MobileAuto-check passed
  • Review Prompt

    gustavscirulis/snapgrid

    Generates smart App Store review prompt infrastructure with configurable conditions and platform detection.

    116 GitHub starsUsed in 1 repo~1.3k tokens
    MobileAuto-check: notes
  • App Store Screenshots Generator

    ParthJadhav/app-store-screenshots

    Scaffolds a Next.js editor for designing App Store and Google Play screenshots as ads and exporting them at every required size, for iOS, Mac and Android.

    7.2k GitHub stars~16k tokensUpdated yesterday
    MobileAuto-check passed

More from robinebers/openusage

All 25 skills in this repo
  • Swiftui Patterns

    robinebers/openusage

    Best practices and example-driven guidance for building native macOS SwiftUI scenes and components, including windows, commands, toolbars, settings, split views, inspectors, menu bar extras, and…

    4.3k GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • macOS Telemetry

    robinebers/openusage

    Add and verify lightweight macOS runtime telemetry. An agent skill from robinebers/openusage.

    4.3k GitHub stars~934 tokensUpdated yesterday
    Auto-check passed
  • Release Swift

    robinebers/openusage

    Cut a release of OpenUsage (Swift menu-bar app): pick a version, generate a categorized changelog, tag from main, and publish the GitHub Release with notes.

    4.3k GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Telemetry

    robinebers/openusage

    Add lightweight runtime telemetry and debug instrumentation to macOS apps, then verify those events after building and running.

    4.3k GitHub stars~977 tokensUpdated yesterday
    Auto-check passed
  • Window Management

    robinebers/openusage

    Customize macOS 15+ SwiftUI windows and scene behavior using Window, WindowGroup, and macOS window modifiers.

    4.3k GitHub stars~2.6k tokensUpdated yesterday
    Auto-check passed
  • Appkit Interop

    robinebers/openusage

    Decide when and how to bridge a macOS app from SwiftUI into AppKit.

    4.3k GitHub stars~741 tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Signing Entitlements

What does Signing Entitlements do?

Inspect signing, entitlements, hardened runtime, and Gatekeeper issues for macOS apps. Signing Entitlements is an agent skill from robinebers/openusage. Inspect signing, entitlements, hardened runtime, and Gatekeeper issues for macOS apps.

When should I use Signing Entitlements?

Signing Entitlements fits situations like: asked to diagnose code signing failures; missing entitlements; sandbox problems; notarization prerequisites.

How do I install Signing Entitlements in Claude Code?

Run `npx skills add robinebers/openusage --skill signing-entitlements -a claude-code`. Or copy the skill folder (.agents/skills/signing-entitlements in robinebers/openusage) into .claude/skills/signing-entitlements in your project. Claude Code loads it when a task matches its description.

How do I install Signing Entitlements in Codex?

Run `npx skills add robinebers/openusage --skill signing-entitlements -a codex`. Or copy the skill folder (.agents/skills/signing-entitlements in robinebers/openusage) into .agents/skills/signing-entitlements in your project. Codex loads it when a task matches its description.

Can I use Signing Entitlements in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add robinebers/openusage --skill signing-entitlements -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/signing-entitlements, .gemini/skills/signing-entitlements, .github/skills/signing-entitlements and .opencode/skills/signing-entitlements in your project.

What does Signing Entitlements need to run?

SKILL.md names no scripts, command-line tools or credentials: Signing Entitlements is instructions for the agent only.

Does Signing Entitlements access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Signing Entitlements safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Signing Entitlements use?

Signing Entitlements is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Signing Entitlements use?

About 468 tokens (SKILL.md is roughly 1.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Signing Entitlements?

Skills that share tags, products or a category with Signing Entitlements: Workbuddy Skin Studio (cdredfox/workbuddy-skin-studio, 197 stars), Store Screenshots (pandulapeter/campfire, 101 stars), iOS Accessibility (dpearson2699/swift-ios-skills, 1.2k stars) and Hunt macOS (Encod3d-Sec/TORCH, 329 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Signing Entitlements?

robinebers (a GitHub user) maintains it in robinebers/openusage, which has 4,341 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on October 10, 2026.

Source: robinebers/openusage on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.