CtrlK
BlogDocsLog inGet started
Tessl Logo

signing-entitlements

Inspect macOS signing, entitlements, and Gatekeeper issues. Use when diagnosing code signing, sandbox, hardened runtime, or trust failures.

71

Quality

86%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

86%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-crafted, lean diagnostic skill: copy-paste-ready commands, a clear classify-then-fix workflow, useful guardrails against common conflations, and explicit output expectations. The main improvement space is a small amount of concrete interpretation guidance — example codesign/spctl output patterns and a sample repair command — which would lift actionability and workflow closure to top marks.

Suggestions

Actionability: add one-line expected-output cues for the key commands (e.g., what `Authority=adhoc` or `rejected (the code is valid but does not satisfy the specified policy)` from spctl/codesign indicates), so classification is directly grounded in observed output.

Actionability: include a minimal repair example such as `codesign --force --deep --sign - <path>` for the local ad-hoc case, since the workflow promises 'the shortest set of validation or repair commands' but only validation commands are shown.

Workflow clarity: close the loop with an explicit re-validation step after a proposed fix (re-run `codesign -dvvv` / `spctl -a -vv` to confirm the failure class is resolved).

DimensionReasoningScore

Conciseness

The body is lean and efficient with zero padding — "Use this skill when the failure smells like codesigning rather than compilation" goes straight to trigger conditions, and no section explains concepts Claude already knows. Every token earns its place, matching the anchor 5 example of terse, well-labeled sections.

5 / 5

Actionability

Concrete, executable commands are given verbatim ("codesign -dvvv --entitlements :- <path>", "spctl -a -vv <path>", "security find-identity -p codesigning -v") plus a concrete seven-class failure taxonomy. It stops short of anchor 5 because there are no example command outputs to interpret and no repair/re-sign command despite the body asking for a "set of validation or repair commands".

4 / 5

Workflow Clarity

A clear four-step sequence (locate binary → read signing details → classify failure → explain minimum fix) with each step's concrete commands. It is not anchor 5 because validation is implicit in the diagnostic commands rather than an explicit validate-and-recover loop (e.g., re-checking after applying a fix), though the operation is diagnostic and non-destructive so no cap applies.

4 / 5

Progressive Disclosure

The skill is a short (~54-line), single-purpose instruction skill with well-organized sections (Quick Start, Workflow, Useful Commands, Guardrails, Output Expectations) and no external bundle files; the body references no missing files (verified: no references/, scripts/, or assets/ directories exist). Per the rubric's simple-skill note, well-organized sections alone earn the top score.

5 / 5

Total

18

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it explicitly states both what the skill does and when to use it, in third person, with concrete natural-language trigger terms and a clearly distinct macOS niche. Its only weakness is a slightly thin action list and a few missing common synonyms like notarization.

DimensionReasoningScore

Specificity

"Inspect macOS signing, entitlements, and Gatekeeper issues" names several specific concrete capabilities with a clear action verb. It falls short of anchor 5 because coverage has minor gaps (no repair, notarization, or identity-management actions), but exceeds anchor 3 by naming three distinct specific targets rather than only 1-2 actions.

4 / 5

Completeness

"Inspect macOS signing, entitlements, and Gatekeeper issues" explicitly states what the skill does, and "Use when diagnosing code signing, sandbox, hardened runtime, or trust failures" explicitly states when to use it with concrete trigger phrases — an exact match to the anchor 5 example pattern.

5 / 5

Trigger Term Quality

Natural user phrases like "code signing", "sandbox", "hardened runtime", and "trust failures" plus "Gatekeeper" and "entitlements" give good keyword coverage. A few common natural terms are missing (e.g., "notarization", "provisioning profile", "codesign"), so it matches anchor 4 rather than the comprehensive synonym coverage of anchor 5.

4 / 5

Distinctiveness Conflict Risk

"macOS signing" with "Gatekeeper" and "hardened runtime" is a clear niche with distinct triggers, matching the anchor 5 for minimal conflict risk; it would not fire for unrelated skills.

5 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
openai/plugins
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.