Audit Xcode Security Settings
superagents-lab/xcode27-skills
Audit and enable security-oriented Xcode build settings. An agent skill from superagents-lab/xcode27-skills.
维护、审查、重构、现代化或调试 Objective-C iOS 项目。用于 .h/.m/.mm、UIKit/Auto Layout/滚动/渲染/启动、ARC/block/线程/CF bridge、KVC/KVO/runtime/swizzling、Swift 混编、Xcode 构建依赖、废弃…
$ npx skills add sun6762/objc-ios-maintenance --skill objc-ios-maintenance -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install sun6762/objc-ios-maintenance objc-ios-maintenance --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
Claude Code skills documentation · loads skills from .claude/skills/
Install the "objc-ios-maintenance" agent skill from https://github.com/sun6762/objc-ios-maintenance/tree/main into .claude/skills/objc-ios-maintenance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "objc-ios-maintenance", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sun6762/objc-ios-maintenance --skill objc-ios-maintenance -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install sun6762/objc-ios-maintenance objc-ios-maintenance --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "objc-ios-maintenance" agent skill from https://github.com/sun6762/objc-ios-maintenance/tree/main into .agents/skills/objc-ios-maintenance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "objc-ios-maintenance", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sun6762/objc-ios-maintenance --skill objc-ios-maintenance -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install sun6762/objc-ios-maintenance objc-ios-maintenance --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "objc-ios-maintenance" agent skill from https://github.com/sun6762/objc-ios-maintenance/tree/main into .cursor/skills/objc-ios-maintenance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "objc-ios-maintenance", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sun6762/objc-ios-maintenance --skill objc-ios-maintenance -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install sun6762/objc-ios-maintenance objc-ios-maintenance --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "objc-ios-maintenance" agent skill from https://github.com/sun6762/objc-ios-maintenance/tree/main into .gemini/skills/objc-ios-maintenance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "objc-ios-maintenance", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install sun6762/objc-ios-maintenance objc-ios-maintenanceInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add sun6762/objc-ios-maintenance --skill objc-ios-maintenance -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "objc-ios-maintenance" agent skill from https://github.com/sun6762/objc-ios-maintenance/tree/main into .github/skills/objc-ios-maintenance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "objc-ios-maintenance", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sun6762/objc-ios-maintenance --skill objc-ios-maintenance -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install sun6762/objc-ios-maintenance objc-ios-maintenance --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "objc-ios-maintenance" agent skill from https://github.com/sun6762/objc-ios-maintenance/tree/main into .opencode/skills/objc-ios-maintenance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "objc-ios-maintenance", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
objc-ios-maintenance维护、审查、重构、现代化或调试 Objective-C iOS 项目。用于 .h/.m/.mm、UIKit/Auto Layout/滚动/渲染/启动、ARC/block/线程/CF bridge、KVC/KVO/runtime/swizzling、Swift 混编、Xcode 构建依赖、废弃…
Objc iOS Maintenance is an agent skill from sun6762/objc-ios-maintenance. 维护、审查、重构、现代化或调试 Objective-C iOS 项目。用于 .h/.m/.mm、UIKit/Auto Layout/滚动/渲染/启动、ARC/block/线程/CF bridge、KVC/KVO/runtime/swizzling、Swift 混编、Xcode 构建依赖、废弃 API/隐私合规、崩溃符号化/dSYM/MetricKit、EXCBADACCESS/OOM/watchdog、网络缓存、数据持久化、重构安全网、安全审计、推送后台、静态扫描工具链和新手 OC + UIKit 架构。
Its SKILL.md is about 6.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 69 other files, including scripts, reference files and assets (for example `README.md` and `agents/openai.yaml`).
It sits in Mobile, covering iOS development. It works with Objective-C, iOS and Xcode. The repository describes itself as: Objective-C iOS maintenance skill for legacy UIKit apps. Helps review, refactor, debug, and write safer OC code with guidance on ARC ownership, retain cycles, KVO/KVC, Swift… The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 947a2a6. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/, which the agent can run.
Shell commands in SKILL.md call:
python3xcodebuildFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Objc iOS Maintenance loads about 6.3k tokens when it runs, and up to ~67k if it reads all its reference files. Until then it costs about 70 tokens; SKILL.md has 1,558 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from sun6762/objc-ios-maintenance at commit 947a2a6, republished under its MIT licence (© sun6762). 1,558 words, ~6,318 tokens.
.claude/skills/objc-ios-maintenance/SKILL.md (or your agent's skills folder). This skill also uses 65 other files; get the full folder from GitHub.当任务涉及 Objective-C iOS 代码库时使用这个 skill。维护既有项目时,默认采用小范围、兼容调用方、尊重运行时行为的方式;从零编写 OC + UIKit 功能或用户经验不清晰时,默认进入“新手安全层”,优先生成保守、可取消、主线程安全、少运行时魔法的代码。
这个 skill 是 Objective-C iOS 旧项目维护的总入口,覆盖常见 UIKit、ARC、runtime、Swift 混编、废弃 API/合规适配、性能和崩溃问题。它按 SKILL.md + references/ + scripts/ + assets/ 的通用 Agent Skill 结构组织,可被 Codex 和 Claude Code 读取。保持“一个总 skill + 多个 references”的组织方式;不要把它拆成多个子 skill,除非用户后续明确要求。
直接处理:
.h、.m、.mm 代码审查、修复、重构和现代化。.xcconfig、CocoaPods、SPM、静态库/闭源二进制、-ObjC/-force_load、category 符号裁剪、modulemap/PCH 和编译速度治理。PrivacyInfo.xcprivacy、Required Reason API、ATT/IDFA、权限体系、刘海屏/安全区、Dark Mode、Dynamic Type 和 iPad 多窗口。NSNotificationCenter 收敛。beginBackgroundTask 和 BGTaskScheduler。xcodebuild analyze、Infer、OCLint、-Wall warning 基线和 CI 分级治理。不直接处理:
当前会话中,这个 skill 的维护目录为 /Users/bobo/develop/objc-ios-maintenance。后续对该 skill 的增补、翻译、脚本和资源维护都在这个目录下进行。若将 skill 复制到其他机器,按复制后的 skill 根目录解析相对路径。
按 Codex / Claude Code 兼容的 Agent Skill 结构维护如下:
objc-ios-maintenance/
├── SKILL.md # 必需:skill 入口、触发描述、核心工作流与引用路由
├── agents/
│ └── openai.yaml # 推荐:用于 Codex/OpenAI UI 展示;Claude Code 可忽略
├── scripts/ # 可选:放可执行脚本;当前包含 Objective-C 风险巡检脚本
├── references/ # 可选:放按需读取的长文档;当前存放 Objective-C 维护专题资料
├── assets/ # 可选:放模板、图片、字体、示例工程等资源;当前包含 UIView 渲染性能分类和 weak proxy 模板
└── evals/ # 可选:放 skill 行为评测用例,用于后续回归验证维护这个 skill 时,保持 SKILL.md 精简,只放触发信息、工作流、核心规则和引用路由;把较长的专题说明放入 references/,并从 SKILL.md 明确说明什么时候读取。
.mm、生成的 Swift 头文件、bridging header、category、swizzling、KVO、associated object 或 CoreFoundation 所有权。.h 文件当作 API 契约处理。修改 nullability、generics、selector 名称时要考虑 Swift 导入结果和所有调用方。当用户明确说自己是新手、不懂 iOS、不熟 Objective-C/UIKit,或要求“从零写页面/搭架构/写基础功能”,以及用户经验水平不清晰时,默认进入新手安全模式,并读取 references/beginner-uikit-architecture.md。
新手安全模式的默认立场:
@try/@catch 吞异常。references/runtime-crash-guard.md。先按用户任务选择最少 reference:
references/beginner-uikit-architecture.md。references/performance-diagnostics.md,必要时运行 scripts/scan_objc_risks.py,再按命中类别读取具体 reference。NSNotificationCenter 泛滥,读 references/refactoring-safety-net.md。references/security-audit.md。beginBackgroundTask、后台 URLSession 或 BackgroundTasks,读 references/push-background.md。xcodebuild analyze、Infer、OCLint、-Wall、几千条 warning、baseline、CI 静态扫描或警告分级治理,读 references/static-analysis-toolchain.md。references/memory-ownership.md;涉及内存上涨、缓存、NSCache、imageNamed、图片 downsampling、大图解码或 @autoreleasepool 峰值,再读 references/memory-leaks-performance.md。references/errors-async-threading.md;涉及共享状态、死锁、串行队列重入、QoS 优先级反转、OSSpinLock、锁、GCD 线程膨胀、atomic 误用或乱序覆盖,再读 references/concurrency-safety.md。references/networking-caching.md。NSUserDefaults、Keychain、文件读写、归档/反归档、Core Data、SQLite/FMDB、离线数据、数据迁移、备份策略或本地敏感数据保护,读 references/data-persistence.md。references/corefoundation-bridging.md。EXC_BAD_ACCESS、SIGSEGV、KERN_INVALID_ADDRESS、objc_msgSend 崩溃、野指针、Zombie、Address Sanitizer/ASan、Malloc Scribble、Guard Malloc、use-after-free、double free、over-release、assign 对象或 __unsafe_unretained,读 references/dangling-pointer-diagnostics.md。0x8badf00d、启动/前后台切换超时或主线程长时间无响应,读 references/oom-watchdog-diagnostics.md。atos、Xcode Organizer、第三方 SDK dSYM、MetricKit、MXMetricManager、MXDiagnosticPayload、MXCrashDiagnostic 或 MXHangDiagnostic,读 references/crash-symbolication-metrickit.md。references/crash-prevention.md,再按分类读取内存、线程、runtime、UIKit 或 CoreFoundation reference。references/runtime-kvo-categories.md;涉及崩溃边界,再读 references/crash-prevention.md。references/runtime-crash-guard.md。这是非默认方案,只用于历史包袱兜底。-Swift.h 或 Swift 导入质量,读 references/swift-interop.md。references/legacy-uikit.md。references/scrolling-performance.md;涉及 Auto Layout/Masonry 动态布局,再读 references/layout-performance.md。references/uikit-rendering-performance.md。+load 统计、SDK 初始化或启动热路径,读 references/startup-performance.md。project.pbxproj、target/scheme、.xcconfig、CocoaPods、SPM、静态库、闭源 .a、xcframework、-ObjC、-force_load、category 符号裁剪、头文件依赖、PCH、umbrella header、modulemap 或编译速度,读 references/build-system-dependencies.md。UIWebView/WKWebView、AddressBook、ALAssetsLibrary、UIAlertView/UIActionSheet、PrivacyInfo.xcprivacy、Required Reason API、ATT/IDFA、相册 Limited、精确定位、安全区、Dark Mode、Dynamic Type 或 iPad 多窗口,读 references/compliance-adaptation.md。只读取当前任务需要的 reference:
references/memory-ownership.md:属性修饰符、delegate 所有权、retain cycle、weak/strong dance、timer、notification、associated object 循环引用。references/beginner-uikit-architecture.md:新手安全层、OC + UIKit 保守架构、默认禁用项、ViewController/Service/Model/Cell 职责、可复制模板使用。references/refactoring-safety-net.md:无测试老代码重构安全网、characterization test、OCMock、快照测试、Massive ViewController 拆分、单例和 NSNotificationCenter 收敛。references/security-audit.md:ATS 例外、明文 HTTP、SSL pinning、硬编码密钥、WKWebView JS bridge 注入面、deep link、本地敏感数据和越狱检测。references/push-background.md:APNs 证书到 p8 token auth 迁移、device token、推送接收、notification extension、静默推送、beginBackgroundTask、BackgroundTasks 和后台 URLSession。references/static-analysis-toolchain.md:clang static analyzer、xcodebuild analyze、Infer、OCLint、warning baseline、CI 门禁和老项目警告分级治理。references/errors-async-threading.md:NSError **、completion handler、URLSession/GCD/NSOperation 约定、主线程 UI 更新。references/corefoundation-bridging.md:CFBridgingRetain、CFBridgingRelease、__bridge、__bridge_transfer、Create/Copy/Get 所有权规则。references/runtime-kvo-categories.md:KVC/KVO 崩溃边界、manual KVO、context 指针、category、associated object、method swizzling。references/runtime-crash-guard.md:运行时兜底、防崩溃分类、完全消息转发、集合/KVO swizzling 止血和不可 runtime 兜底边界。非默认方案,只用于历史包袱兜底。references/swift-interop.md:bridging header、module、生成的 -Swift.h、影响 Swift 导入的 nullability/generics、NS_SWIFT_NAME、NS_REFINED_FOR_SWIFT。references/legacy-uikit.md:view controller 生命周期、table/collection cell 复用、Auto Layout、delegate/data source 维护。references/uikit-rendering-performance.md:UIKit 渲染性能、离屏渲染、圆角、阴影、mask、透明混合、shouldRasterize、列表滚动视觉效果优化。references/scrolling-performance.md:UITableView/UICollectionView 滚动性能、cell 复用、复用标识符、预估行高、异步图片、图片 downsampling、图片预解码、约束复用、高度缓存、prefetch、列表刷新卡顿。references/layout-performance.md:Auto Layout 性能、约束创建/更新、动态高度、Masonry remakeConstraints、frame 混用、约束冲突。references/startup-performance.md:启动性能、pre-main、dyld、动态库数量、+load / +initialize、AppDelegate / SceneDelegate、首屏、SDK 初始化、启动热路径瘦身。references/memory-leaks-performance.md:内存上涨、页面不释放、图片内存、imageNamed 缓存语义、ImageIO downsampling、NSCache、autoreleasepool、timer/display link/observer 生命周期。references/crash-prevention.md:崩溃治理分层、分类矩阵、治理闭环、集合 nil/越界、类型校验、列表批量更新一致性、KVC/KVO 崩溃、动态 selector、全局防崩溃分类风险。references/crash-symbolication-metrickit.md:崩溃日志符号化、dSYM/UUID 匹配、dSYM 归档、第三方 SDK 符号、MetricKit 接入、MXCrashDiagnostic / MXHangDiagnostic 和线上诊断闭环。references/dangling-pointer-diagnostics.md:EXC_BAD_ACCESS、SIGSEGV、objc_msgSend 野指针崩溃、Zombie、ASan、Malloc Scribble、Guard Malloc、use-after-free、double free 和 CF/C/C++ 内存访问诊断。references/oom-watchdog-diagnostics.md:OOM、Jetsam、FOOM、memory warning、内存峰值、缓存膨胀、watchdog、0x8badf00d、启动/前后台切换超时和主线程卡死诊断。references/concurrency-safety.md:GCD、NSOperation、共享 mutable state、主队列 dispatch_sync、串行队列重入、QoS 优先级反转、OSSpinLock 到 os_unfair_lock/锁迁移、GCD 线程膨胀、atomic 边界、竞态、取消语义、异步结果时序、completion 队列契约。references/networking-caching.md:NSURLSession、请求取消、重复请求合并、缓存 key、弱网重试、分页刷新、网络回调 UI 安全。references/data-persistence.md:NSUserDefaults、Keychain 后台访问时机、文件存储、NSCoding 到 NSSecureCoding、Core Data 跨线程访问、轻量迁移失败兜底、SQLite/FMDB 线程安全与 WAL、离线数据、迁移、备份策略和本地敏感数据保护。references/performance-diagnostics.md:Instruments、Core Animation、Leaks、Zombies、Main Thread Checker、静态风险巡检和性能优化记录。references/build-system-dependencies.md:Xcode 工程、project.pbxproj 合并冲突、target/scheme 漂移、.xcconfig 分层、CocoaPods/SPM 混用、静态库 category 符号裁剪、-ObjC / -force_load、闭源 .a 到 xcframework、头文件/PCH/modulemap 和编译速度治理。references/compliance-adaptation.md:废弃 API 迁移、UIWebView 到 WKWebView、JS bridge 白名单、cookie/session、Contacts、Photos、隐私清单、Required Reason API、ATT/IDFA、权限体系、安全区、Dark Mode、Dynamic Type 和 iPad 多窗口。进行审查或修复建议时,优先使用下面结构,按任务复杂度裁剪:
如果用户要求直接改代码,完成后汇报修改文件、行为变化和已运行验证。不要把 scripts/scan_objc_risks.py 的命中结果直接当作确定缺陷;它只是 review 线索。
assets/snippets/UIView+OCMPerformance.hassets/snippets/UIView+OCMPerformance.massets/snippets/OCMWeakProxy.hassets/snippets/OCMWeakProxy.massets/snippets/OCMCrashSafety.hassets/snippets/OCMCrashSafety.massets/snippets/webview/OCMWebView.hassets/snippets/webview/OCMWebView.massets/snippets/webview/OCMWebViewFactory.hassets/snippets/webview/OCMWebViewFactory.massets/snippets/webview/OCMWebCookieCoordinator.hassets/snippets/webview/OCMWebCookieCoordinator.massets/snippets/webview/OCMWebSecurityPolicy.hassets/snippets/webview/OCMWebSecurityPolicy.massets/snippets/webview/OCMWeakScriptMessageDelegate.hassets/snippets/webview/OCMWeakScriptMessageDelegate.massets/templates/beginner-uikit/OCMItem.hassets/templates/beginner-uikit/OCMItem.massets/templates/beginner-uikit/OCMItemService.hassets/templates/beginner-uikit/OCMItemService.massets/templates/beginner-uikit/OCMItemListViewModel.hassets/templates/beginner-uikit/OCMItemListViewModel.massets/templates/beginner-uikit/OCMItemCell.hassets/templates/beginner-uikit/OCMItemCell.massets/templates/beginner-uikit/OCMItemListViewController.hassets/templates/beginner-uikit/OCMItemListViewController.m当用户明确需要 UIView 渲染性能工具分类时,参考或复制这两个文件。复制到业务项目后,建议把 OCM 方法前缀替换为项目自己的前缀,避免 category 方法名冲突。不要把模板当作全局自动优化工具;它只提供显式调用的圆角、阴影、shadowPath、透明背景和 rasterize 辅助方法。
当用户需要处理 NSTimer / CADisplayLink 持有 target 导致页面不释放时,参考或复制 OCMWeakProxy 模板。weak proxy 只能打断 target 循环引用,仍要在生命周期边界调用 invalidate。
当用户需要处理集合 nil/越界、外部 JSON 类型收敛或后台回调更新 UI 时,参考或复制 OCMCrashSafety 模板。它只提供显式调用的 helper,不改变 Foundation/UIKit 全局行为;调用点仍要处理空数据和降级状态。
当用户需要迁移 UIWebView 到 WKWebView、统一 JS bridge 白名单或 cookie/session 边界时,参考或复制 assets/snippets/webview/。这组模板提供页面级 OCMWebView 子类、factory、cookie coordinator、安全白名单和 weak script message delegate;不要把 OCMWebView 做全局单例,也不要把业务路由、支付、分享等 native 能力塞进模板。
当用户是新手或从零写 OC + UIKit 列表/网络页面时,优先参考 assets/templates/beginner-uikit/。这些模板展示保守分层、nullability/generics、可取消网络、主线程 completion、稳定 reuse identifier、generation token 和外部数据类型收敛。复制后要替换 OCM 前缀,并贴合项目既有网络层和图片加载库。
scripts/scan_objc_risks.pyscripts/test_scan_objc_risks.py当用户需要先盘点 Objective-C 项目的性能、崩溃和运行时风险时,可以运行该脚本。脚本输出是人工 review 线索,不是确定缺陷;不要机械替换所有命中项。
python3 scripts/scan_objc_risks.py /path/to/YourProject
python3 scripts/scan_objc_risks.py /path/to/YourProject --category rendering
python3 scripts/scan_objc_risks.py /path/to/YourProject --category build
python3 scripts/scan_objc_risks.py /path/to/YourProject --category compliance
python3 scripts/scan_objc_risks.py /path/to/YourProject --category persistence
python3 scripts/scan_objc_risks.py /path/to/YourProject --category runtime
python3 scripts/scan_objc_risks.py /path/to/YourProject --category security
python3 scripts/scan_objc_risks.py /path/to/YourProject --category background
python3 scripts/scan_objc_risks.py /path/to/YourProject --category toolchain
python3 scripts/scan_objc_risks.py /path/to/YourProject --min-level warning
python3 scripts/scan_objc_risks.py /path/to/YourProject --format json --max-findings 50
python3 scripts/scan_objc_risks.py /path/to/YourProject --fail-on-finding维护扫描脚本后,运行 python3 scripts/test_scan_objc_risks.py 验证多行匹配、JSON 输出和 CI 失败开关。
strong。NSString、NSAttributedString、NSArray、NSDictionary、NSSet、NSData、NSIndexSet 以及其他具有值语义的对象使用 copy,因为调用方可能传入 mutable 子类。copy。栈上的 block 一旦需要逃逸出当前作用域,就必须被复制。weak。标量和 C struct 使用 assign。assign;如果必须使用,写清楚生命周期假设。nonatomic,除非既有 API 明确承诺 atomic 属性语义。atomic 不等于对象状态线程安全。copy、weak delegate、可取消异步任务和主线程 UI 更新。NSNull、错误类型、越界 index 或 nil 插入集合进入 UI 层。prepareForReuse 重置、异步结果检查稳定 model identifier。self:block 属性、被对象保留的动画 block、operation 持有的 completion block、timer、display link、block 形式的 notification observer。__weak typeof(self) weakSelf = self;
[self.service loadWithCompletion:^(id result, NSError *error) {
__strong typeof(weakSelf) self = weakSelf;
if (!self) {
return;
}
[self handleResult:result error:error];
}];NS_ASSUME_NONNULL_BEGIN / NS_ASSUME_NONNULL_END 包裹,再把真实可空的位置标为 nullable。NSArray<NSString *> *、NSDictionary<NSString *, NSNumber *> *、NSSet<MyModel *> *。instancetype。id<MyDelegate>,再按实际情况加 nullable 或 weak。NSError **,在显式 nullability 的头文件中优先写成 NSError * _Nullable * _Nullable error。BOOL 或 nullable object;只在失败时写入 *error,写入前必须检查 error != NULL。userInfo key。不要一边返回部分成功值一边设置 error。(ResultType _Nullable result, NSError *_Nullable error),并文档化或强制回调队列。__bridge。__bridge_transfer 或 CFBridgingRelease。__bridge_retained 或 CFBridgingRetain。CFRelease。observeValueForKeyPath:ofObject:change:context: 中处理自己的 context。willChangeValueForKey: 和 didChangeValueForKey: 包裹。dispatch_once,调用原实现,并记录受影响 selector。.h 文件里 import 生成的 ProductModuleName-Swift.h。在头文件中使用 forward declaration,在 .m 文件里按需 import 生成的 Swift 头。NS_SWIFT_NAME、NS_REFINED_FOR_SWIFT 改善 Swift 导入质量。unrecognized selector 若 selector 来自静态库/Pod/闭源 .a 中的 category,优先检查最终 App/Extension target 的 OTHER_LDFLAGS 是否保留 $(inherited) 并包含必要的 -ObjC。-force_load 只对有证据的单个静态库使用,并记录原因;不要用全局 -all_load 作为长期兜底。project.pbxproj 冲突后必须跑 plutil -lint、xcodebuild -list 和关键 target/configuration 的 -showBuildSettings。.xcconfig 要分层清楚,避免 Xcode UI、Podfile post_install 和 xcconfig 多处重复设置同一项;可继承设置保留 $(inherited)。.a 迁移 xcframework 时同步验证 headers、modulemap/umbrella header、dSYM、BCSymbolMaps、资源和 license。.h 尽量 forward declare,把具体 import 放到 .m/.mm,避免递归 Header Search Paths。xcodebuild -showBuildTimingSummary 基线,再分别处理头文件依赖、PCH、script phase、Pods/SPM 缓存和链接方式。UIWebView 必须从源码、storyboard/xib、第三方 SDK 和最终二进制中清干净;迁移目标是 WKWebView,不是兼容包装旧 API。WKWebView 本身做全局单例。可以共享 factory、WKProcessPool、WKWebsiteDataStore / cookie 协调器和白名单策略;每个页面仍持有自己的 web view。AddressBook 迁移到 Contacts 时重新设计授权、keysToFetch、联系人标识和变更通知;不要把 ABRecordID 当长期稳定 ID。ALAssetsLibrary 迁移到 Photos/PHPicker 时处理 Limited、add-only/read-write、取消选择和继续选择路径。UIAlertView / UIActionSheet 迁移到 UIAlertController 时,iPad action sheet 必须配置 popover 锚点。PrivacyInfo.xcprivacy 是 target 级交付物。App、framework 和第三方 SDK 都要盘点 collected data、tracking、tracking domains 和 Required Reason API。viewDidLoad;每次显示前需要刷新的内容放在 viewWillAppear:;依赖最终 frame 的布局放在 viewDidLayoutSubviews;cleanup/cancellation 放在与既有所有权匹配的生命周期方法中。prepareForReuse 中重置临时状态并取消过期异步任务。translatesAutoresizingMaskIntoConstraints = NO。respondsToSelector:。shadowPath,内层 view 负责 cornerRadius 和必要的裁剪。shadowPath 时要重点审查,尤其是在 table/collection cell 中。mask、masksToBounds、透明混合和 shouldRasterize 都需要结合场景验证;不要把 UIView 分类写成自动修改所有 view 行为的万能工具。prepareForReuse 取消旧任务并重置状态,异步回调必须检查稳定 model identifier。constant 或 active;动态高度缓存要包含宽度、内容版本和字体环境。didFinishLaunching、首帧和可交互阶段;+load / +initialize 不做业务初始化、IO、数据库或大型 SDK 启动。atomic 不等于线程安全;共享 mutable collection 必须通过串行队列、锁或同一 concurrent queue + barrier 保护。dispatch_sync(dispatch_get_main_queue(), ...);后台结果更新 UI 前切回主队列。dispatch_sync 回同一队列;需要同步快照时使用 queue-specific key 或重新设计为异步边界。OSSpinLock 应迁移到 os_unfair_lock、NSLock 或串行队列;持锁期间只做短内存临界区,不调用外部 block/delegate、IO 或同步派发。NSOperationQueue.maxConcurrentOperationCount、NSURLSession 或分批背压。NSUserDefaults 只存小体积非敏感偏好;token、session、password 和私钥进入 Keychain,并处理 OSStatus、accessibility、账号隔离和退出登录清理。NSFileProtection 和错误返回;可重建缓存不要放在会备份的用户文档目录。NSSecureCoding 和 allowed classes;Core Data / SQLite 访问要遵守队列、事务、迁移和错误处理契约。NSManagedObjectID 或 DTO,不跨队列传 NSManagedObject;所有 context 访问进入自己的 performBlock: / performBlockAndWait:。FMDatabaseQueue,启用 WAL 时同步考虑 busy timeout、checkpoint 和 -wal/-shm 备份。constant / active。makeConstraints,状态变化用 updateConstraints,避免在滚动热路径高频 remakeConstraints。copy、delegate/timer/observer/KVO 未清理、associated object 隐藏循环引用或误用 ASSIGN。dispatch_sync 死锁,atomic 被当成集合线程安全,阻塞任务无界丢到 global queue。+load swizzling 无 dispatch_once/签名检查,category selector 冲突,消息转发伪造签名,KVC/KVO 边界靠吞异常兜底。-ObjC,$(inherited) 被覆盖,project.pbxproj 冲突后未核对 target/scheme/configuration。shadowPath。imageNamed: 用于大图/下载图,原图先解码再缩小,无上限缓存或 NSCache 缺 cost/key。id 未做类型收敛,列表批量更新数量不一致,请求 owner/取消/去重/缓存 key/重试边界不清。NSUserDefaults,文件目录/备份/原子写错误,旧归档无 NSSecureCoding,Core Data/SQLite 队列和迁移失败路径不清。UIWebView,WKWebView/JS bridge 无白名单,ATS/证书校验放开,客户端硬编码 secret 或 APNs p8 私钥。instancetype、Swift 导入、错误返回和 completion 队列是否清晰?-ObjC/-force_load、PCH/modulemap 和 dSYM 是否可复现?© sun6762, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 65 other files (scripts, references, assets) in the repository root of sun6762/objc-ios-maintenance.
Open the folder on GitHubat commit 947a2a6
Objc iOS Maintenance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Objc iOS Maintenance this skillsun6762/objc-ios-maintenance | 181 | — | ~6.3k | Automated safety check: Pass | MIT | |
| Audit Xcode Security Settingssuperagents-lab/xcode27-skills | 338 | — | ~4.6k | Automated safety check: Pass | None | |
| Debug Rn Native CrashLedgerHQ/ledger-live | 622 | — | ~1.2k | Automated safety check: Pass | MIT | |
| Orca iOS Simulator Controlstablyai/orca | 87k | 1 repos | ~584 | Automated safety check: Pass | Apache-2.0 | |
| Apple Crash Log .NET Symbolicationdotnet/skills | 5.6k | 1 repos | ~2.4k | Automated safety check: Pass | MIT | |
| Update Swiftui APIsAvdLee/SwiftUI-Agent-Skill | 3.7k | — | ~1.2k | Automated safety check: Pass | MIT |
superagents-lab/xcode27-skills
Audit and enable security-oriented Xcode build settings. An agent skill from superagents-lab/xcode27-skills.
LedgerHQ/ledger-live
Investigate native React Native crashes (Fabric/Hermes/iOS) in ledger-live-mobile when JS error logs are missing or unhelpful.
stablyai/orca
iOS Simulator control from inside Orca, with the live device view in Orca's emulator pane. Use when driving a booted Apple Simulator on macOS: taps, gestures…
dotnet/skills
Resolves .NET runtime frames in Apple .ips crash logs to function names, source files and line numbers using dSYM symbols, atos and the Microsoft symbol server.
AvdLee/SwiftUI-Agent-Skill
Scan Apple's SwiftUI documentation for deprecated APIs and update the SwiftUI Expert Skill with modern replacements.
conorluddy/ios-simulator-skill
29 production-ready scripts for iOS app testing, building, and automation.
Works with
Categories
维护、审查、重构、现代化或调试 Objective-C iOS 项目。用于 .h/.m/.mm、UIKit/Auto Layout/滚动/渲染/启动、ARC/block/线程/CF bridge、KVC/KVO/runtime/swizzling、Swift 混编、Xcode 构建依赖、废弃…. Objc iOS Maintenance is an agent skill from sun6762/objc-ios-maintenance.
Objc iOS Maintenance fits situations like: tasks that involve iOS development.
Run `npx skills add sun6762/objc-ios-maintenance --skill objc-ios-maintenance -a claude-code`. Or copy the skill folder (the sun6762/objc-ios-maintenance repository) into .claude/skills/objc-ios-maintenance in your project. Claude Code loads it when a task matches its description.
Run `npx skills add sun6762/objc-ios-maintenance --skill objc-ios-maintenance -a codex`. Or copy the skill folder (the sun6762/objc-ios-maintenance repository) into .agents/skills/objc-ios-maintenance in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sun6762/objc-ios-maintenance --skill objc-ios-maintenance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/objc-ios-maintenance, .gemini/skills/objc-ios-maintenance, .github/skills/objc-ios-maintenance and .opencode/skills/objc-ios-maintenance in your project.
Going by SKILL.md and its folder, Objc iOS Maintenance needs the command-line tools its instructions call (python3 and xcodebuild).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Objc iOS Maintenance is published under the MIT licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.
About 6.3k tokens (SKILL.md is roughly 25k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 60k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Objc iOS Maintenance: Audit Xcode Security Settings (superagents-lab/xcode27-skills, 338 stars), Debug Rn Native Crash (LedgerHQ/ledger-live, 622 stars), Orca iOS Simulator Control (stablyai/orca, 87k stars) and Apple Crash Log .NET Symbolication (dotnet/skills, 5.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
sun6762 (a GitHub user) maintains it in sun6762/objc-ios-maintenance, which has 181 GitHub stars. The repository was last updated on July 26, 2026.
Source: sun6762/objc-ios-maintenance on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.