Agent skill

Mac Fleet Maintenance

by steipete in steipete/agent-scripts

Inventories and maintains a fleet of Macs from a desired-state file: package updates, repo and Xcode sync, and disk, backup and security health reports.

MITAuto-check passedDevOps & Cloud

Install Mac Fleet Maintenance

skills CLI
$ npx skills add steipete/agent-scripts --skill fleet-maintenance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install steipete/agent-scripts fleet-maintenance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/steipete/agent-scripts.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/fleet-maintenance .claude/skills/fleet-maintenance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fleet-maintenance
GitHub stars
7.3k
Token cost
~4.8k tokens
SKILL.md length
2,207 words
Files
16 (incl. scripts, references)
Skills in repo
45
Repo updated
First seen
Licence
MIT

At a glance

Inventories and maintains a fleet of Macs from a desired-state file: package updates, repo and Xcode sync, and disk, backup and security health reports.

  • Works in 7 steps: Resolve the host's full or worker… → Sync eligible repos using the existing… → Update Homebrew and global npm packages… → …
  • Auditing which apps and packages are installed across several Macs
  • SKILL.md covers Desired state, Safety contract, Run order and Preflight, plus 9 more sections
  • Runs Shell and JavaScript scripts from its folder; calls brew, node and git

What it does

The skill compares what should be installed, from an inventory file with two profiles (full for daily-driver Macs and worker for lean remote machines), against what is actually there. Profile policy is a minimum: required entries get installed, extras are reported but not removed, and observed software never silently becomes desired state. It collects installed apps and packages, audits references to local-account escrow, and keeps topology and SSH routing in a separate file.

Maintenance covers Homebrew and global package updates, safe repository sync, Xcode sync through a companion skill, and health reports on disk, services, backups, updates and security. Secrets such as passwords and keys stay in 1Password with only item IDs in the inventory, and SSH between hosts relies on a mesh over Tailscale with per-host authorized keys. The skill ships mostly shell audit scripts, plus a fleet profile script and a schema reference. The paths and companion skills it names are specific to its author's own setup.

When your agent uses it

  • Auditing which apps and packages are installed across several Macs
  • Updating Homebrew and global packages on a fleet without losing local work
  • Checking disk, backup, service and security health on remote Macs
  • Verifying that SSH between fleet machines works in both directions

Example prompts

  • “Compare the worker profile with what is actually installed on my remote Mac and list what is missing.”
  • “Update Homebrew and global packages across the fleet and report anything that broke.”
  • “Run the host health audit on every Mac and summarize disk and backup problems.”

Requirements

  • Mac hosts reachable over SSH
  • An inventory.json desired-state file
  • The 1Password CLI
  • Homebrew

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Resolve the host's full or worker profile, collect observed inventory, and run package-ownership preflight.
  2. Sync eligible repos using the existing Git/toolchain.
  3. Update Homebrew and global npm packages on every eligible, reachable host regardless of active agents/services.
  4. Verify each host's macOS stable/beta track.
  5. Sync Xcode through $xcode-sync.
  6. Empty Trash only when explicitly requested for this run; perform approved package cleanup.
  7. Re-audit disk, tools, package ownership, repos, memory, and role-critical services.

What it can do on your machine

Read from SKILL.md and the folder at commit d9f70f4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 13 files in scripts/ (Shell and JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • brew
    • node
    • git
    • npm
    • ssh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, npm and ssh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Mac Fleet Maintenance loads about 4.8k tokens when it runs, and up to ~7k if it reads all its reference files. Until then it costs about 79 tokens; SKILL.md has 2,207 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~79
When it runs · the whole SKILL.md, loaded when a task matches
~4.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from steipete/agent-scripts at commit d9f70f4, republished under its MIT licence (© steipete). 2,207 words, ~4,819 tokens.

Download SKILL.mdSave it as .claude/skills/fleet-maintenance/SKILL.md (or your agent's skills folder). This skill also uses 15 other files; get the full folder from GitHub.
name
fleet-maintenance
description
Mac fleet inventory and upkeep with full/worker profiles: collect installed apps and packages, compare desired versus observed state, audit local-account escrow references, update Homebrew/global packages, safely sync repos and Xcode, and report disk, service, backup, update, and security health.

Fleet Maintenance

Maintain Peter's Macs while protecting ambiguous local work. Package updates are explicitly allowed during active sessions and may disrupt the software being upgraded. Use $remote-mac for inventory/SSH and $xcode-sync for all Xcode work.

Desired state

  • Read ~/Projects/manager/fleet/inventory.json for desired software and local-account escrow references. Read references/fleet-schema.md before changing its schema or adopting packages.
  • Keep exactly two profiles unless Peter explicitly changes the model:
    • full: daily-driver Macs with the complete development, communication, media, and agentic toolset.
    • worker: lean remote Macs that mainly run Codex, Claude, OpenClaw nodes, and supporting agent infrastructure.
  • Treat profile policy as minimum: install required entries and report extras without removing them. Never silently turn observed software into desired state.
  • Keep topology, SSH routing, and handed-off status in ~/Projects/manager/computers.yaml. Do not duplicate live topology in this skill.
  • Keep passwords, recovery keys, and private keys in 1Password. The inventory stores opaque item IDs only. Invoke $one-password before any op command; a pending reference is not an error during package maintenance.
  • Require the classic OpenSSH mesh named by ssh_mesh on both profiles. The manager fleet setup document owns the canonical peer list and live proof. Use the symmetric Tailscale TCP 22 grant plus per-host authorized_keys; macOS GUI Tailscale clients cannot act as Tailscale SSH servers. Distribute public keys only, keep private keys host-local, verify both directions with BatchMode=yes and a finite timeout, and leave offline or provider-blocked directions pending.
  • Require the stable 1Password CLI integrity baseline on every fleet Mac. Require the file-backed service-account profile block unless that host has a documented requirement_exceptions security boundary in inventory. Audit eligible hosts with scripts/op-profile-audit.sh; audit token-exempt hosts with scripts/op-profile-audit.sh --cli-only. Repair only after $one-password is loaded and the mode-0600 token file is provisioned; never print or store the token in inventory.
  • Require the agent skill mirror on every fleet Mac. Audit it with scripts/agent-skill-links-audit.sh; its --repair invokes broad canonical sync only when both canonical repos exist. Sync preserves real directories and files, accepting same-directory local ownership and reporting other real destination conflicts. For reason=nested-self-link, invoke the reviewed sync owner directly by absolute path with --repair-nested-self-links --dry-run -- NAME..., then omit --dry-run to remove only validated nested leaves; preserve the real Claude skill directories and Codex backlinks. This narrow loop check is not an exhaustive graph validator. See references/fleet-schema.md for scope and ~/Projects/manager/docs/fleet-setup.md for fleet setup.
  • Require the shared global Git ignore on every fleet Mac. Audit it with scripts/global-gitignore-audit.sh; --repair creates ~/.config/git/ignore, preserves unrelated entries, adds the inventory's macOS metadata patterns, and points core.excludesFile at it. An already-configured alternate excludes file requires manual review so existing rules are never discarded.
  • Require Claude Code and Claude Desktop coding sessions to omit AI attribution. Audit ~/.claude/settings.json with scripts/claude-attribution-audit.sh; --repair preserves unrelated settings while disabling commit trailers, pull-request footers, and remote-session links.
  • Require the official Codex and Claude Code CLIs on both profiles. Package ownership comes from the profile's codex and claude-code Homebrew casks; the separate claude cask is Claude Desktop and does not satisfy the CLI requirement. Audit versions and non-interactive authentication with scripts/agent-cli-audit.sh; use --live for bounded, tool-free, non-persistent model turns. Never copy normal Claude OAuth credentials between Macs: refresh each host independently through $anthropic and leave locked-Keychain, account-selection, or offline cases pending.
  • Require Octopool as the GitHub cache on both profiles with requirements.github_cache: "octopool". Package presence alone is insufficient: scripts/octopool-audit.sh must prove that non-interactive and login zsh resolve gh through the Octopool shim, the client login has complete identity metadata, and every configured pool identity is healthy. Use --repair to log in through the existing authenticated stable-path GitHub CLI, install the zsh shim, and repair macOS login PATH ordering when needed; it never installs packages or prints credentials.

Use the deterministic profile tool:

bash
node skills/fleet-maintenance/scripts/fleet-profile.mjs collect
node skills/fleet-maintenance/scripts/fleet-profile.mjs \
  plan --fleet ~/Projects/manager/fleet/inventory.json \
  --host mac-studio-sf --snapshot /path/to/mac-studio-sf.json
node skills/fleet-maintenance/scripts/fleet-profile.mjs \
  diff --source /path/to/macbook-pro.json --target /path/to/mac-studio-sf.json
node skills/fleet-maintenance/scripts/fleet-profile.mjs \
  brewfile --fleet ~/Projects/manager/fleet/inventory.json --host mac-studio-sf
node skills/fleet-maintenance/scripts/fleet-profile.mjs \
  validate --fleet ~/Projects/manager/fleet/inventory.json
skills/fleet-maintenance/scripts/agent-skill-links-audit.sh
skills/fleet-maintenance/scripts/global-gitignore-audit.sh --host mac-studio-sf
skills/fleet-maintenance/scripts/claude-attribution-audit.sh
skills/fleet-maintenance/scripts/agent-cli-audit.sh
skills/fleet-maintenance/scripts/octopool-audit.sh
skills/fleet-maintenance/scripts/op-profile-audit.sh

Collector snapshots are observed evidence, not configuration. Store reviewed snapshots under ~/Projects/manager/fleet/snapshots/<host-id>.json. diff reports source-only candidates; Peter chooses which enter full.

Safety contract

  • Read ~/Projects/manager/computers.yaml; use live Tailscale state and deduplicate hosts by hardware UUID. Exclude handed-off and unknown machines.
  • Audit hosts in parallel; mutate one host at a time. Recheck agent activity immediately before every repo or Xcode mutation.
  • Skip repositories with a user process cwd inside them or a Git lock. Recent files are audit signal, not a blocker. Permit dirty worktrees only through the conflict-free fast-forward procedure below.
  • Homebrew and global npm updates are allowed while agents/services are running. This can mix old in-memory code with replaced files, break later imports or child processes, and let Homebrew terminate/reopen cask GUI apps. Accept that package-update risk; never manually terminate or restart services. Verify health and report interruptions or pending restarts.
  • Never reset, clean, stash, rebase, switch branches, delete local work, push, install macOS updates, or reboot during routine maintenance.
  • Snapshot role-critical services before package updates. Do not restart OpenClaw gateways or other services unless explicitly authorized; verify them afterward using their owning skill.
  • Keep a per-host action log. An unreachable host is pending, never current.

Run order

  1. Resolve the host's full or worker profile, collect observed inventory, and run package-ownership preflight.
  2. Sync eligible repos using the existing Git/toolchain.
  3. Update Homebrew and global npm packages on every eligible, reachable host regardless of active agents/services.
  4. Verify each host's macOS stable/beta track.
  5. Sync Xcode through $xcode-sync.
  6. Empty Trash only when explicitly requested for this run; perform approved package cleanup.
  7. Re-audit disk, tools, package ownership, repos, memory, and role-critical services.

Preflight

Record hostname, hardware UUID, macOS, architecture, uptime, Tailscale state, selected Xcode, free bytes/percent, Trash size, Homebrew prefix/version, Node/npm versions, running Brew services, active coding-agent processes, and resident-memory outliers:

bash
node skills/fleet-maintenance/scripts/fleet-profile.mjs collect
skills/fleet-maintenance/scripts/host-health-audit.sh 30
ssh -o RequestTTY=no -o RemoteCommand=none HOST 'node --input-type=module - collect' \
  < skills/fleet-maintenance/scripts/fleet-profile.mjs
ssh -o RequestTTY=no -o RemoteCommand=none HOST 'bash -s -- 30' \
  < skills/fleet-maintenance/scripts/host-health-audit.sh

Report every process above 30 GiB resident memory. Do not alert on virtual size alone, sum related processes, or terminate a process automatically. Record PID, resident GiB, user, executable, role, and whether memory remains above the threshold on a second sample.

Classify startup-disk space using both absolute and relative capacity:

  • healthy: at least 100 GiB and 15% free
  • warning: 50–100 GiB or 10–15% free
  • critical: below 50 GiB or 10% free

Do not start Xcode expansion on warning/critical space. Never delete outside Trash, superseded package-manager artifacts, or Xcode paths governed by $xcode-sync without explicit approval.

Repository sync

Run the read-only candidate audit on each host:

bash
skills/fleet-maintenance/scripts/repo-sync-audit.sh ~/Projects 3
ssh -o RequestTTY=no -o RemoteCommand=none HOST 'bash -s -- "$HOME/Projects" 3' \
  < skills/fleet-maintenance/scripts/repo-sync-audit.sh

Apply the audited policy with the bundled updater. It rechecks safety, fetches noninteractively, fast-forwards clean or conflict-free dirty worktrees, and isolates refusals:

bash
skills/fleet-maintenance/scripts/repo-sync-update.sh ~/Projects 3
ssh -o RequestTTY=no -o RemoteCommand=none HOST \
  '"$HOME/Projects/agent-scripts/skills/fleet-maintenance/scripts/repo-sync-update.sh" "$HOME/Projects" 3'

Only process rows marked candidate. Recheck branch, upstream, Git locks, and active process cwd immediately before mutation, then:

bash
git -C "$repo" fetch --prune
git -C "$repo" rev-list --left-right --count HEAD...@{upstream}

Run fetches noninteractively and bound each one (for example five minutes). On timeout, authentication failure, or network failure, terminate that fetch, mark the repo pending, and continue. Never let one stale/private mirror stall the host, rewrite its remote, or prompt for credentials during fleet maintenance.

Interpret counts as ahead behind:

  • 0 0: current; no action.
  • 0 N: inspect git log --oneline HEAD..@{upstream} and git diff --stat HEAD..@{upstream}. Record HEAD and worktree status. Run git merge --ff-only --no-autostash --no-overwrite-ignore @{upstream}. A clean worktree should advance. A dirty worktree may advance only when Git can preserve every local change without overlap; Git refusal means skip-local-overlap, not an error to repair. After success, require no unmerged entries, the expected upstream commit at HEAD, and all prior local modifications still present. After refusal, require unchanged HEAD, no unmerged entries, and unchanged worktree status.
  • N 0 or N M: inspect local commit subjects/authors and git diff --stat @{upstream}...HEAD; explain likely intent and escalate. Never push or rewrite.
  • detached/no upstream/fetch failure: understand remotes, branches, recent commits, and worktree state; escalate with the smallest useful decision.

Do not infer that a stale local checkout should match a sibling checkout. Each visible checkout is user-managed.

Never use pull or merge as a conflict resolver. Never pass --autostash, create a stash, discard changes, or stage files. A non-fast-forward, checkout-overwrite warning, merge conflict, or changed safety snapshot stops that repository only; continue the fleet pass.

Show full SKILL.md (911 more words)Show less

Homebrew

Skip only if Homebrew is absent. Running agents/services do not block package mutation:

First render the host's resolved profile to a temporary Brewfile and run brew bundle check --verbose --file FILE. Review missing entries. brew bundle install --file FILE may install or upgrade declared dependencies. Never run brew bundle cleanup --force; extras are allowed under the default minimum policy. Remove an entry only through an explicitly approved prune action.

Homebrew 6 can refuse third-party formulae until they are trusted. If that happens, verify each formula is already declared in the resolved fleet profile, then grant trust to those exact formula names with brew trust --formula .... Never trust an entire tap or a formula discovered only from the remote tap. Record the resulting trust list with brew trust --json v1 and resume the same generated Brewfile.

bash
brew update
brew outdated --json=v2
brew upgrade
brew services list
brew doctor

Treat brew doctor as advisory; do not blindly apply its suggestions. Compare services before/after. Use brew cleanup --prune=30 after successful verification; use more aggressive cleanup only for disk pressure and explicit approval.

If an upgrade replaces Node, Git, Codex, or another executable used by an active agent/service, accept that later imports or child processes may observe new files and report the risk. Allow Homebrew's controlled quit/reopen for cask GUI apps, including possible session termination; do not manually restart services, change taps, or uninstall packages automatically.

Package ownership

Run scripts/host-health-audit.sh before and after package mutations. Investigate its ownership candidates plus duplicate launchd labels/listeners, executable version skew, and collisions across Homebrew formulae/casks, global npm, standalone apps, and app-bundled CLIs.

For each candidate, resolve executable realpaths, package receipts, service definitions, listeners, running processes, dependents, versions, and intended host role. Prefer one canonical owner. Disable or uninstall a redundant owner only when its replacement is healthy, no installed package depends on it, and the current request authorizes the fix. Never infer a conflict from a shared name alone; formula/app pairs can be intentional.

Global npm packages

“Update npm” means registry-backed, top-level global packages—not project dependencies. Never change a repository's package.json or lockfile here.

  1. Record node --version, npm --version, npm prefix -g, and npm ls -g --depth=0 --json.
  2. Run npm outdated -g --depth=0 --json; its nonzero exit can mean updates exist.
  3. Update each registry package to name@latest. Skip linked, file, Git, bundled, and ambiguous packages; report them.
  4. Let the owner update npm itself: Homebrew updates a Homebrew Node/npm; only use npm install -g npm@latest for a self-managed npm installation. Verify the resulting npm --version.
  5. Re-run inventory and smoke-test the updated global CLIs. Use $npm and $one-password only if a private package actually requires registry authentication; never expose npm credentials.

Major global-package updates are intended even when the package currently backs an active coding agent or service. Accept the risk of mixed old/new files; do not restart the process. Smoke-test the newly installed CLI separately and report failures or pending restarts.

macOS track

Record sw_vers product/build and current beta-seed enrollment. Resolve the latest stable and current beta build from authoritative current Apple sources; do not hardcode versions or infer track from version number alone. Use softwareupdate --list to confirm what the host is actually offered on its configured track.

Classify each Mac as current, update available, track ambiguous, unsupported, or unreachable. Preserve its configured stable/beta track. Routine maintenance does not switch tracks, install macOS updates, or reboot: prepare the exact update and request a maintenance window after confirming no active agents/services and adequate backup/disk state.

Xcode

Invoke $xcode-sync; do not duplicate its install logic. Resolve current stable/beta/RC versions from an authoritative current source, not hardcoded versions. Preserve each host's selected stable or prerelease track while maintaining the canonical stable/prerelease slots and previous-major retention policy defined there.

Verify product build, signature, first-launch state, selection, host compatibility, and free space. Report unsupported and unreachable Macs separately.

Simulator hygiene is a required fleet invariant, not optional disk cleanup. Run the $xcode-sync simulator-hygiene audit on every reachable Mac. A host without Xcode/simctl is not-applicable; a host with Xcode is current only when Apple reports no outdated or unusable runtime images and no devices tied to unavailable runtimes. Repair only after checking for active Xcode work; the canonical action refuses while simulator devices are booted.

Trash and disk

Measure Trash on every run. Keep it read-only unless the current request explicitly says to clear/empty Trash. With that consent, empty only the current user's home-volume Trash after resolving and verifying the path:

bash
trash="$HOME/.Trash"
home_real=$(cd "$HOME" && pwd -P)
trash_real=$(cd "$trash" && pwd -P)
if [[ "$trash_real" != "$home_real/.Trash" ]]; then
  printf 'refusing unexpected Trash path: %s\n' "$trash_real" >&2
  exit 2
fi
find "$trash_real" -mindepth 1 -maxdepth 1 -exec rm -rf {} +

Never empty another user's Trash or Trash on external volumes. Recheck disk capacity afterward; escalate unexplained growth instead of broad cache deletion.

Baseline health checks

Include these read-only checks in the report; mutations need separate authority:

  • available macOS/security updates and whether a reboot is recommended
  • Mac App Store application drift via mas outdated, when mas is installed
  • last successful Time Machine backup, when configured
  • SMART/storage warnings and APFS volume health signals available from diskutil
  • uptime, clock synchronization, and laptop battery health/cycle count
  • Tailscale reachability/version drift
  • failed Brew services and role-specific LaunchAgents/daemons
  • FileVault, firewall, Gatekeeper, and SIP status drift
  • Developer ID certificate and important SSH credential expiry dates, never secret values

Useful optional maintenance: stale package caches/logs, abandoned containers/VMs, old device-support files not managed by CoreSimulator, orphaned launch agents, and large Downloads. Audit first; delete only with explicit scope.

Finish

Return a host matrix with: reachability, agent CLI install/auth/live-test state, Octopool shim/login/pool-health state, agent skill-link state, global Git-ignore state, active/deferred reason, disk before/after, Trash reclaimed, Brew/npm changes, repos pulled/current/skipped/escalated, Xcode stable/prerelease build and selected track, backup/update/service warnings, and remaining user decisions.

© steipete, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 15 other files (scripts, references) in skills/fleet-maintenance of steipete/agent-scripts.

  • SKILL.md
  • agents/openai.yaml
  • references/fleet-schema.md
  • scripts/agent-cli-audit.sh
  • scripts/agent-skill-links-audit.sh
  • scripts/claude-attribution-audit.sh
  • scripts/fleet-profile.mjs
  • scripts/global-gitignore-audit.sh
  • scripts/host-health-audit.sh
  • scripts/octopool-audit.sh
  • scripts/op-profile-audit.sh
  • scripts/repo-sync-audit.sh
  • scripts/repo-sync-update.sh
  • scripts/test-agent-cli-audit.sh
  • scripts/test-fleet-profile.sh
  • scripts/test-octopool-audit.sh

Open the folder on GitHubat commit d9f70f4

Compare with similar skills

Mac Fleet Maintenance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Mac Fleet Maintenance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Mac Fleet Maintenance this skillsteipete/agent-scripts7.3k—~4.8kAutomated safety check: PassMIT
Running GitHub Actions Efficientlykajisho5/ffmpeg-skill1.9k—~3.3kAutomated safety check: NotesMIT
Sicurezza GitHubccplugins/awesome-claude-code-plugins970—~486Automated safety check: NotesApache-2.0
Local Dev Setupmohitagw15856/pm-claude-skills1.4k—~4.6kAutomated safety check: NotesMIT
CodexBar macOS Releasesteipete/CodexBar22k—~1.5kAutomated safety check: PassMIT
Daytona Sandbox Operationsdifferent-ai/openwork24k—~917Automated safety check: PassCustom licence

Similar skills

  • Cut GitHub Actions minutes and wall-clock time without losing coverage — the OS billing multiplier (macOS 10x / Windows 2x / Linux 1x), trigger hygiene that stops push+pullrequest double-firing…

    1.9k GitHub stars~3.3k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Sicurezza GitHub

    ccplugins/awesome-claude-code-plugins

    Aggiunge alle repository GitHub dei siti workflow di sicurezza automatici - scansione dipendenze vulnerabili, ricerca di segreti/chiavi nel codice, analisi statica CodeQL e Dependabot.

    970 GitHub stars~486 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Local Dev Setup

    mohitagw15856/pm-claude-skills

    Write a local development environment setup guide for a service or project — covering prerequisites, repository setup, environment variables, local service dependencies, database seeding, running…

    1.4k GitHub stars~4.6k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • CodexBar macOS Release

    steipete/CodexBar

    Releases a signed, notarized CodexBar build: confirms the changelog, resolves signing credentials from 1Password, runs the release script in tmux, and updates the Sparkle appcast and Homebrew tap.

    22k GitHub stars~1.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Daytona Sandbox Operations

    different-ai/openwork

    Covers Daytona CLI setup, sandbox debugging, keeping a sandbox alive and which credentials the CLI uses, for when Daytona itself is the problem rather than the tests.

    24k GitHub stars~917 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Triaging Security Findings

    bitwarden/ai-plugins

    Official

    This skill should be used when the user asks to "triage security findings", "fix an Aikido finding", "review Aikido issues", "dismiss a false positive", "check SAST/IaC alerts", or needs to work…

    155 GitHub stars~2.2k tokensUpdated today
    SecurityAuto-check passed

More from steipete/agent-scripts

All 45 skills in this repo
  • Agent Transcript for PRs

    steipete/agent-scripts

    Finds a coding agent's session log, trims and redacts it, and inserts it into a GitHub PR or issue only when the user has asked for a transcript.

    7.3k GitHub starsUsed in 1 repo~698 tokens
    Auto-check passed
  • Parallels macOS VM Lab

    steipete/agent-scripts

    Uses a clean Parallels macOS VM to test GUI automation, TCC permission prompts and screenshot tools like Peekaboo, verifying results from outside the guest.

    7.3k GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • ClawSweeper Status

    steipete/agent-scripts

    Reports ClawSweeper's status with a bundled script: workflow health, active workers, queue health and recently merged, reviewed, commented and closed items.

    7.3k GitHub stars~972 tokensUpdated today
    Auto-check passed
  • GitHub Project Triage

    steipete/agent-scripts

    Produces maintainer-facing triage cards for a project's GitHub issues and pull requests, each with its URL, risk, test state, blockers and a next action.

    7.3k GitHub stars~4k tokensUpdated today
    Auto-check passed
  • Nano Banana Image Generation

    steipete/agent-scripts

    Generates and edits images with Google's Nano Banana 2 (Gemini 3.1 Flash Image) through a uv script, with a draft-then-final workflow and sizes from 512 to 4K.

    7.3k GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • npm Registry Operations

    steipete/agent-scripts

    Handles npm registry tasks such as whoami checks, package name availability, name reservation and publishing, with credentials pulled from 1Password.

    7.3k GitHub stars~1.1k tokensUpdated today
    Auto-check passed

Works with

Questions about Mac Fleet Maintenance

What does Mac Fleet Maintenance do?

Inventories and maintains a fleet of Macs from a desired-state file: package updates, repo and Xcode sync, and disk, backup and security health reports. The skill compares what should be installed, from an inventory file with two profiles (full for daily-driver Macs and worker for lean remote machines), against what is actually there. Profile policy is a minimum: required entries get installed, extras are reported but not removed, and observed software never silently becomes desired state.

When should I use Mac Fleet Maintenance?

Mac Fleet Maintenance fits situations like: auditing which apps and packages are installed across several Macs; updating Homebrew and global packages on a fleet without losing local work; checking disk, backup, service and security health on remote Macs; verifying that SSH between fleet machines works in both directions.

How do I install Mac Fleet Maintenance in Claude Code?

Run `npx skills add steipete/agent-scripts --skill fleet-maintenance -a claude-code`. Or copy the skill folder (skills/fleet-maintenance in steipete/agent-scripts) into .claude/skills/fleet-maintenance in your project. Claude Code loads it when a task matches its description.

How do I install Mac Fleet Maintenance in Codex?

Run `npx skills add steipete/agent-scripts --skill fleet-maintenance -a codex`. Or copy the skill folder (skills/fleet-maintenance in steipete/agent-scripts) into .agents/skills/fleet-maintenance in your project. Codex loads it when a task matches its description.

Can I use Mac Fleet Maintenance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add steipete/agent-scripts --skill fleet-maintenance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fleet-maintenance, .gemini/skills/fleet-maintenance, .github/skills/fleet-maintenance and .opencode/skills/fleet-maintenance in your project.

What does Mac Fleet Maintenance need to run?

Going by SKILL.md and its folder, Mac Fleet Maintenance needs a shell and JavaScript for the scripts in its folder and the command-line tools its instructions call (brew, node, git, npm and ssh). Our summary lists: Mac hosts reachable over SSH; An inventory.json desired-state file; The 1Password CLI; Homebrew.

Does Mac Fleet Maintenance access the network?

SKILL.md contains no URLs. Its commands use git, npm and ssh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Mac Fleet Maintenance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Mac Fleet Maintenance use?

Mac Fleet Maintenance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Mac Fleet Maintenance use?

About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.2k tokens, read only when the agent opens those files.

What are the alternatives to Mac Fleet Maintenance?

Skills that share tags, products or a category with Mac Fleet Maintenance: Running GitHub Actions Efficiently (kajisho5/ffmpeg-skill, 1.9k stars), Sicurezza GitHub (ccplugins/awesome-claude-code-plugins, 970 stars), Local Dev Setup (mohitagw15856/pm-claude-skills, 1.4k stars) and CodexBar macOS Release (steipete/CodexBar, 22k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Mac Fleet Maintenance?

steipete (a GitHub user) maintains it in steipete/agent-scripts, which has 7,323 GitHub stars. The repository holds 45 skills in this directory. The repository was last updated on October 10, 2026.

Source: steipete/agent-scripts on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.