App Store Review
safaiyeh/app-store-review-skill
Evaluates code against Apple's App Store Review Guidelines. An agent skill from safaiyeh/app-store-review-skill.
Reverse engineer and security-review macOS applications and Mach-O binaries — thinning universal binaries, recovering Objective-C/Swift structure, reading code-signing entitlements and the hardened…
$ npx skills add trilwu/secskills --skill analyzing-macos-binaries -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trilwu/secskills analyzing-macos-binaries --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-core/skills/analyzing-macos-binaries .claude/skills/analyzing-macos-binaries && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "analyzing-macos-binaries" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/analyzing-macos-binaries into .claude/skills/analyzing-macos-binaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-macos-binaries", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trilwu/secskills/tree/main/secskills-core/skills/analyzing-macos-binariesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trilwu/secskills --skill analyzing-macos-binaries -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trilwu/secskills analyzing-macos-binaries --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/secskills-core/skills/analyzing-macos-binaries .agents/skills/analyzing-macos-binaries && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "analyzing-macos-binaries" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/analyzing-macos-binaries into .agents/skills/analyzing-macos-binaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-macos-binaries", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill analyzing-macos-binaries -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trilwu/secskills analyzing-macos-binaries --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/secskills-core/skills/analyzing-macos-binaries .cursor/skills/analyzing-macos-binaries && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "analyzing-macos-binaries" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/analyzing-macos-binaries into .cursor/skills/analyzing-macos-binaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-macos-binaries", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trilwu/secskills.git --path secskills-core/skills/analyzing-macos-binaries--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trilwu/secskills --skill analyzing-macos-binaries -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trilwu/secskills analyzing-macos-binaries --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/secskills-core/skills/analyzing-macos-binaries .gemini/skills/analyzing-macos-binaries && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "analyzing-macos-binaries" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/analyzing-macos-binaries into .gemini/skills/analyzing-macos-binaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-macos-binaries", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trilwu/secskills analyzing-macos-binariesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trilwu/secskills --skill analyzing-macos-binaries -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .github/skills && cp -r skills-src/secskills-core/skills/analyzing-macos-binaries .github/skills/analyzing-macos-binaries && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "analyzing-macos-binaries" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/analyzing-macos-binaries into .github/skills/analyzing-macos-binaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-macos-binaries", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill analyzing-macos-binaries -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trilwu/secskills analyzing-macos-binaries --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/secskills-core/skills/analyzing-macos-binaries .opencode/skills/analyzing-macos-binaries && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "analyzing-macos-binaries" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/analyzing-macos-binaries into .opencode/skills/analyzing-macos-binaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-macos-binaries", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
analyzing-macos-binariesReverse engineer and security-review macOS applications and Mach-O binaries — thinning universal binaries, recovering Objective-C/Swift structure, reading code-signing entitlements and the hardened…
Analyzing macOS Binaries is an agent skill from trilwu/secskills. Reverse engineer and security-review macOS applications and Mach-O binaries — thinning universal binaries, recovering Objective-C/Swift structure, reading code-signing entitlements and the hardened runtime, and auditing XPC services, dylib load paths, and TCC privacy exposure. Use when analyzing a .app bundle or Mach-O on macOS, checking entitlements and notarization, hunting a dylib-hijack or XPC privilege bug, or reasoning about Gatekeeper and quarantine.
Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Mobile, covering App store release, iOS development and Security review. It works with macOS and Objective-C. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.
Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Analyzing macOS Binaries loads about 1.7k tokens when it runs. Until then it costs about 122 tokens; SKILL.md has 850 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 850 words, ~1,699 tokens.
.claude/skills/analyzing-macos-binaries/SKILL.md (or your agent's skills folder).macOS reverse engineering is Mach-O plus a specific security model: code signing, entitlements, the sandbox, TCC privacy, and XPC between processes. The binary tells you what the code does; the entitlements and load paths tell you what it is allowed to do and where an attacker could get in. Read both — most macOS findings live in the gap between the two.
.app bundle or a Mach-O executable/dylib/framework on macOS@rpath and weak dylibscryptid=1), App Store binaries —
are analyzing-ios-binaries. Same Mach-O format, different toolchain and DRM.analyzing-binaries.exploiting-memory-corruption.unpacking-protected-binaries.lipo -thin (or lipo -archs to list) so your tools work on one slice.otool -l for load commands, otool -L for linked
dylibs and their paths, nm for symbols. Note the load commands that matter
later: LC_RPATH, LC_LOAD_DYLIB / LC_LOAD_WEAK_DYLIB, and the code
signature.Contents/MacOS (the binary), Info.plist (identifiers,
URL schemes), _CodeSignature, embedded Frameworks/, and any bundled
XPCServices/. The bundle layout is the map of what to analyze.class-dump (or dsdump)
reconstructs class, method, and property declarations straight from the
binary. This is the fastest way to see the app's structure.swift-demangle over symbols to get readable names, and expect to lean on the
decompiler (Hopper, Ghidra, IDA) more than with Objective-C.class-dump returns little is normal, not a failure.This is where macOS-specific authority lives:
codesign -dvvv --entitlements :- <binary> dumps the signature and the
entitlements — the capabilities the OS grants. Entitlements like
com.apple.security.get-task-allow (debuggable), disabled library validation,
or private TCC entitlements are the high-value reads.com.apple.quarantine extended attribute; Gatekeeper checks notarization on
first run. Understand the quarantine/notarization state when reasoning about
what will execute and what a user was warned about.@rpath
that resolves to a writable location, or a LC_LOAD_WEAK_DYLIB that is absent,
lets an attacker drop a malicious dylib and get code execution in the app's
context — inheriting its entitlements. Enumerate the load paths and check which
are attacker-writable and unprotected by library validation.SMJobBless root helper). The classic bug is a
helper that authorizes a client by PID — which races and is spoofable —
instead of by audit_token. Trace how the service validates its caller and
what privileged action it will perform; weak validation is local privilege
escalation.Info.plist handlers register the app to handle input
from other apps and the web — an untrusted-input entry point.Frida attaches to macOS processes for runtime hooking; lldb debugs (subject to
get-task-allow/SIP); dtrace traces syscalls and library calls where SIP
permits. Use these to watch XPC messages and dylib loads live rather than
inferring them from the binary alone.
swift-demangle and the
decompiler rather than concluding there is nothing to see.audit_token-based validation is sound; a PID check is
the finding.analyzing-ios-binaries for FairPlay IPAs; this skill for
the macOS app and its XPC/TCC/dylib surface.analyzing-ios-binaries — iOS IPAs, FairPlay, and mobile toolchainanalyzing-binaries — general Mach-O triage and decompilation techniqueexploiting-memory-corruption — exploiting a native bug found hereunpacking-protected-binaries — when the Mach-O is packed/encrypted first© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in secskills-core/skills/analyzing-macos-binaries of trilwu/secskills.
Open the folder on GitHubat commit ca53957
Analyzing macOS Binaries next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Analyzing macOS Binaries this skilltrilwu/secskills | 157 | — | ~1.7k | Automated safety check: Pass | MIT | |
| App Store Reviewsafaiyeh/app-store-review-skill | 366 | 1 repos | ~3.4k | Automated safety check: Pass | MIT | |
| OdevioOdevio/Odevio-CLI | 423 | — | ~7.6k | Automated safety check: Pass | MIT | |
| Releasevaayne/mori | 303 | — | ~1.2k | Automated safety check: Pass | MIT | |
| Asc Xcode Buildrorkai/app-store-connect-cli-skills | 1.1k | 2 repos | ~2.1k | Automated safety check: Pass | MIT | |
| Releasemovieclaw/MovieClaw | 151 | — | ~2.6k | Automated safety check: Pass | Custom licence |
safaiyeh/app-store-review-skill
Evaluates code against Apple's App Store Review Guidelines. An agent skill from safaiyeh/app-store-review-skill.
Odevio/Odevio-CLI
Take a Flutter project to an iPhone or the App Store with Odevio - build, sign and publish iOS apps from Windows, Linux or macOS with no Mac and no Xcode.
vaayne/mori
Release workflow for Mori macOS workspace terminal and MoriRemote iOS app.
rorkai/app-store-connect-cli-skills
Build, archive, generate export options, export, upload, and manage Xcode version/build numbers with the current asc xcode helpers.
movieclaw/MovieClaw
发布 movieclaw 新版本。当用户要求发版、发布新版本、打 tag、发布 NER 模型、发布 Docker 镜像,或打包上传 iOS App 到 TestFlight / App Store、补传发版附件(IPA、Mac 转码器、Mac 版 App)时使用。涵盖版本号三处同步、应用/模型/镜像/iOS 的完整流程、可选附件失败补救与检查清单。
nikships/droidproxy
Build, sign, notarize, and publish a new DroidProxy release.
trilwu/secskills
Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.
trilwu/secskills
Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.
trilwu/secskills
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
trilwu/secskills
Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.
trilwu/secskills
Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…
trilwu/secskills
Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…
Works with
Categories
Reverse engineer and security-review macOS applications and Mach-O binaries — thinning universal binaries, recovering Objective-C/Swift structure, reading code-signing entitlements and the hardened…. Analyzing macOS Binaries is an agent skill from trilwu/secskills. Reverse engineer and security-review macOS applications and Mach-O binaries — thinning universal binaries, recovering Objective-C/Swift structure, reading code-signing entitlements and the hardened runtime, and auditing XPC services, dylib load paths, and TCC privacy exposure.
Analyzing macOS Binaries fits situations like: analyzing a .app bundle; mach-O on macOS; checking entitlements and notarization; hunting a dylib-hijack.
Run `npx skills add trilwu/secskills --skill analyzing-macos-binaries -a claude-code`. Or copy the skill folder (secskills-core/skills/analyzing-macos-binaries in trilwu/secskills) into .claude/skills/analyzing-macos-binaries in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trilwu/secskills --skill analyzing-macos-binaries -a codex`. Or copy the skill folder (secskills-core/skills/analyzing-macos-binaries in trilwu/secskills) into .agents/skills/analyzing-macos-binaries in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill analyzing-macos-binaries -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analyzing-macos-binaries, .gemini/skills/analyzing-macos-binaries, .github/skills/analyzing-macos-binaries and .opencode/skills/analyzing-macos-binaries in your project.
SKILL.md names no scripts, command-line tools or credentials: Analyzing macOS Binaries is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Analyzing macOS Binaries is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.7k tokens (SKILL.md is roughly 6.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Analyzing macOS Binaries: App Store Review (safaiyeh/app-store-review-skill, 366 stars), Odevio (Odevio/Odevio-CLI, 423 stars), Release (vaayne/mori, 303 stars) and Asc Xcode Build (rorkai/app-store-connect-cli-skills, 1.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.
Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.