Agent skill

Analyzing macOS Binaries

by trilwu in trilwu/secskills

Reverse engineer and security-review macOS applications and Mach-O binaries — thinning universal binaries, recovering Objective-C/Swift structure, reading code-signing entitlements and the hardened…

MITAuto-check passedMobile

Install Analyzing macOS Binaries

skills CLI
$ npx skills add trilwu/secskills --skill analyzing-macos-binaries -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trilwu/secskills analyzing-macos-binaries --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-core/skills/analyzing-macos-binaries .claude/skills/analyzing-macos-binaries && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
analyzing-macos-binaries
GitHub stars
157
Token cost
~1.7k tokens
SKILL.md length
850 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Reverse engineer and security-review macOS applications and Mach-O binaries — thinning universal binaries, recovering Objective-C/Swift structure, reading code-signing entitlements and the hardened…

  • Analyzing a .app bundle
  • SKILL.md covers When to Use, When NOT to Use, Triage the Binary and Bundle and Recover Objective-C and Swift, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Mach-O on macOS

What it does

Analyzing macOS Binaries is an agent skill from trilwu/secskills. Reverse engineer and security-review macOS applications and Mach-O binaries — thinning universal binaries, recovering Objective-C/Swift structure, reading code-signing entitlements and the hardened runtime, and auditing XPC services, dylib load paths, and TCC privacy exposure. Use when analyzing a .app bundle or Mach-O on macOS, checking entitlements and notarization, hunting a dylib-hijack or XPC privilege bug, or reasoning about Gatekeeper and quarantine.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Mobile, covering App store release, iOS development and Security review. It works with macOS and Objective-C. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.

When your agent uses it

  • Analyzing a .app bundle
  • Mach-O on macOS
  • Checking entitlements and notarization
  • Hunting a dylib-hijack

Example prompts

  • “/analyzing-macos-binaries”

What it can do on your machine

Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Analyzing macOS Binaries loads about 1.7k tokens when it runs. Until then it costs about 122 tokens; SKILL.md has 850 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~122
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 850 words, ~1,699 tokens.

Download SKILL.mdSave it as .claude/skills/analyzing-macos-binaries/SKILL.md (or your agent's skills folder).
name
analyzing-macos-binaries
description
Reverse engineer and security-review macOS applications and Mach-O binaries — thinning universal binaries, recovering Objective-C/Swift structure, reading code-signing entitlements and the hardened runtime, and auditing XPC services, dylib load paths, and TCC privacy exposure. Use when analyzing a .app bundle or Mach-O on macOS, checking entitlements and notarization, hunting a dylib-hijack or XPC privilege bug, or reasoning about Gatekeeper and quarantine.
verified
2026-08-07

Analyzing macOS Binaries

macOS reverse engineering is Mach-O plus a specific security model: code signing, entitlements, the sandbox, TCC privacy, and XPC between processes. The binary tells you what the code does; the entitlements and load paths tell you what it is allowed to do and where an attacker could get in. Read both — most macOS findings live in the gap between the two.

When to Use

  • Analyzing a .app bundle or a Mach-O executable/dylib/framework on macOS
  • Reading entitlements, hardened-runtime flags, notarization, and Gatekeeper quarantine state
  • Auditing an XPC service or privileged helper for an authorization bug
  • Hunting dylib hijacking / proxying via @rpath and weak dylibs
  • Reasoning about TCC privacy exposure and sandbox escape surface

When NOT to Use

  • iOS apps — IPA decryption, FairPlay (cryptid=1), App Store binaries — are analyzing-ios-binaries. Same Mach-O format, different toolchain and DRM.
  • Non-Mach-O or cross-platform triage with no macOS specifics — analyzing-binaries.
  • Turning a memory-corruption crash into an exploit — exploiting-memory-corruption.
  • A Mach-O that is packed/encrypted before you can read it — unpacking-protected-binaries.

Triage the Binary and Bundle

  • Thin the universal binary. macOS ships fat binaries (x86_64 + arm64); use lipo -thin (or lipo -archs to list) so your tools work on one slice.
  • Read the Mach-O. otool -l for load commands, otool -L for linked dylibs and their paths, nm for symbols. Note the load commands that matter later: LC_RPATH, LC_LOAD_DYLIB / LC_LOAD_WEAK_DYLIB, and the code signature.
  • Walk the bundle. Contents/MacOS (the binary), Info.plist (identifiers, URL schemes), _CodeSignature, embedded Frameworks/, and any bundled XPCServices/. The bundle layout is the map of what to analyze.

Recover Objective-C and Swift

  • Objective-C keeps rich runtime metadata: class-dump (or dsdump) reconstructs class, method, and property declarations straight from the binary. This is the fastest way to see the app's structure.
  • Swift is harder — names are mangled and metadata is less forthcoming. Run swift-demangle over symbols to get readable names, and expect to lean on the decompiler (Hopper, Ghidra, IDA) more than with Objective-C.
  • Note which language dominates before choosing the approach; a Swift binary where class-dump returns little is normal, not a failure.

Code Signing, Entitlements, and Gatekeeper

This is where macOS-specific authority lives:

  • codesign -dvvv --entitlements :- <binary> dumps the signature and the entitlements — the capabilities the OS grants. Entitlements like com.apple.security.get-task-allow (debuggable), disabled library validation, or private TCC entitlements are the high-value reads.
  • Hardened runtime flags restrict code injection and debugging; note whether they are on, and whether library validation is disabled (which allows loading unsigned dylibs — directly relevant to hijacking).
  • Notarization and Gatekeeper. Downloaded files carry the com.apple.quarantine extended attribute; Gatekeeper checks notarization on first run. Understand the quarantine/notarization state when reasoning about what will execute and what a user was warned about.
Show full SKILL.md (408 more words)Show less

The macOS-Specific Bug Surface

  • Dylib hijacking / proxying. A binary that loads a dylib from an @rpath that resolves to a writable location, or a LC_LOAD_WEAK_DYLIB that is absent, lets an attacker drop a malicious dylib and get code execution in the app's context — inheriting its entitlements. Enumerate the load paths and check which are attacker-writable and unprotected by library validation.
  • XPC services and privileged helpers. XPC is the mach-based IPC between an app and its helpers (often a SMJobBless root helper). The classic bug is a helper that authorizes a client by PID — which races and is spoofable — instead of by audit_token. Trace how the service validates its caller and what privileged action it will perform; weak validation is local privilege escalation.
  • TCC privacy. TCC gates access to camera, mic, files, and automation. Look at what the app is entitled to and whether it can be coerced into acting as a confused deputy for a less-privileged process, or whether an injectable dylib inherits its TCC grants.
  • URL schemes and Info.plist handlers register the app to handle input from other apps and the web — an untrusted-input entry point.

Dynamic Analysis

Frida attaches to macOS processes for runtime hooking; lldb debugs (subject to get-task-allow/SIP); dtrace traces syscalls and library calls where SIP permits. Use these to watch XPC messages and dylib loads live rather than inferring them from the binary alone.

Rationalizations to Reject

  • "It's signed and notarized, so it's safe." Signing proves origin, not safety, and says nothing about a dylib-hijack path or an XPC helper that trusts its caller's PID. Read the entitlements and load paths.
  • "class-dump returned almost nothing, the binary is stripped." That is the normal signature of a Swift binary. Switch to swift-demangle and the decompiler rather than concluding there is nothing to see.
  • "The helper checks the client PID, that's authentication." PID checks race and are spoofable. Only audit_token-based validation is sound; a PID check is the finding.
  • "Library validation will stop a malicious dylib." Only if it is enabled. Check for the disable-library-validation entitlement and hardened-runtime state before assuming the load is protected.
  • "This is just the iOS process on a Mac." The DRM, toolchain, and security model differ. Use analyzing-ios-binaries for FairPlay IPAs; this skill for the macOS app and its XPC/TCC/dylib surface.

References

  • analyzing-ios-binaries — iOS IPAs, FairPlay, and mobile toolchain
  • analyzing-binaries — general Mach-O triage and decompilation technique
  • exploiting-memory-corruption — exploiting a native bug found here
  • unpacking-protected-binaries — when the Mach-O is packed/encrypted first

© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in secskills-core/skills/analyzing-macos-binaries of trilwu/secskills.

Open the folder on GitHubat commit ca53957

Compare with similar skills

Analyzing macOS Binaries next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Analyzing macOS Binaries compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Analyzing macOS Binaries this skilltrilwu/secskills157—~1.7kAutomated safety check: PassMIT
App Store Reviewsafaiyeh/app-store-review-skill3661 repos~3.4kAutomated safety check: PassMIT
OdevioOdevio/Odevio-CLI423—~7.6kAutomated safety check: PassMIT
Releasevaayne/mori303—~1.2kAutomated safety check: PassMIT
Asc Xcode Buildrorkai/app-store-connect-cli-skills1.1k2 repos~2.1kAutomated safety check: PassMIT
Releasemovieclaw/MovieClaw151—~2.6kAutomated safety check: PassCustom licence

Similar skills

  • App Store Review

    safaiyeh/app-store-review-skill

    Evaluates code against Apple's App Store Review Guidelines. An agent skill from safaiyeh/app-store-review-skill.

    366 GitHub starsUsed in 1 repo~3.4k tokens
    MobileAuto-check passed
  • Odevio

    Odevio/Odevio-CLI

    Take a Flutter project to an iPhone or the App Store with Odevio - build, sign and publish iOS apps from Windows, Linux or macOS with no Mac and no Xcode.

    423 GitHub stars~7.6k tokensUpdated 15 days ago
    MobileAuto-check passed
  • Release

    vaayne/mori

    Release workflow for Mori macOS workspace terminal and MoriRemote iOS app.

    303 GitHub stars~1.2k tokensUpdated 2 mo ago
    MobileAuto-check passed
  • Asc Xcode Build

    rorkai/app-store-connect-cli-skills

    Build, archive, generate export options, export, upload, and manage Xcode version/build numbers with the current asc xcode helpers.

    1.1k GitHub starsUsed in 2 repos~2.1k tokens
    MobileAuto-check passed
  • Release

    movieclaw/MovieClaw

    发布 movieclaw 新版本。当用户要求发版、发布新版本、打 tag、发布 NER 模型、发布 Docker 镜像,或打包上传 iOS App 到 TestFlight / App Store、补传发版附件(IPA、Mac 转码器、Mac 版 App)时使用。涵盖版本号三处同步、应用/模型/镜像/iOS 的完整流程、可选附件失败补救与检查清单。

    151 GitHub stars~2.6k tokensUpdated today
    MobileAuto-check passed
  • Release

    nikships/droidproxy

    Build, sign, notarize, and publish a new DroidProxy release.

    122 GitHub stars~1.1k tokensUpdated today
    MobileAuto-check passed

More from trilwu/secskills

All 50 skills in this repo
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    157 GitHub stars~3.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

    157 GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Securing AI Systems

    trilwu/secskills

    Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Binaries

    trilwu/secskills

    Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Go Binaries

    trilwu/secskills

    Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing iOS Binaries

    trilwu/secskills

    Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Analyzing macOS Binaries

What does Analyzing macOS Binaries do?

Reverse engineer and security-review macOS applications and Mach-O binaries — thinning universal binaries, recovering Objective-C/Swift structure, reading code-signing entitlements and the hardened…. Analyzing macOS Binaries is an agent skill from trilwu/secskills. Reverse engineer and security-review macOS applications and Mach-O binaries — thinning universal binaries, recovering Objective-C/Swift structure, reading code-signing entitlements and the hardened runtime, and auditing XPC services, dylib load paths, and TCC privacy exposure.

When should I use Analyzing macOS Binaries?

Analyzing macOS Binaries fits situations like: analyzing a .app bundle; mach-O on macOS; checking entitlements and notarization; hunting a dylib-hijack.

How do I install Analyzing macOS Binaries in Claude Code?

Run `npx skills add trilwu/secskills --skill analyzing-macos-binaries -a claude-code`. Or copy the skill folder (secskills-core/skills/analyzing-macos-binaries in trilwu/secskills) into .claude/skills/analyzing-macos-binaries in your project. Claude Code loads it when a task matches its description.

How do I install Analyzing macOS Binaries in Codex?

Run `npx skills add trilwu/secskills --skill analyzing-macos-binaries -a codex`. Or copy the skill folder (secskills-core/skills/analyzing-macos-binaries in trilwu/secskills) into .agents/skills/analyzing-macos-binaries in your project. Codex loads it when a task matches its description.

Can I use Analyzing macOS Binaries in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill analyzing-macos-binaries -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analyzing-macos-binaries, .gemini/skills/analyzing-macos-binaries, .github/skills/analyzing-macos-binaries and .opencode/skills/analyzing-macos-binaries in your project.

What does Analyzing macOS Binaries need to run?

SKILL.md names no scripts, command-line tools or credentials: Analyzing macOS Binaries is instructions for the agent only.

Does Analyzing macOS Binaries access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Analyzing macOS Binaries safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Analyzing macOS Binaries use?

Analyzing macOS Binaries is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Analyzing macOS Binaries use?

About 1.7k tokens (SKILL.md is roughly 6.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Analyzing macOS Binaries?

Skills that share tags, products or a category with Analyzing macOS Binaries: App Store Review (safaiyeh/app-store-review-skill, 366 stars), Odevio (Odevio/Odevio-CLI, 423 stars), Release (vaayne/mori, 303 stars) and Asc Xcode Build (rorkai/app-store-connect-cli-skills, 1.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Analyzing macOS Binaries?

trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.

Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.