CtrlK
BlogDocsLog inGet started
Tessl Logo

macos-packaging-notarization

Prepare macOS packaging and notarization workflows. Use when archiving apps, validating bundles, or explaining distribution-only failures.

64

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.agents/skills/macos-packaging-notarization/SKILL.md

The canonical home for this skill is packaging-notarization in openai/plugins

SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A concise, well-structured diagnostic skill body that stays lean and appropriately scoped without bundle files. Its weakness is executability: the workflow describes what to check but never names the concrete commands or failure signatures needed to act, and the sequence lacks validation checkpoints and recovery guidance.

Suggestions

Add the concrete validation commands Claude should run or recommend, e.g. `codesign --verify --deep --strict --verbose=2 <app>`, `spctl -a -t exec --verbose <app>`, and `xcrun notarytool history/submit ...`, so the 'minimum follow-up validation commands' step is actionable rather than deferred.

Insert validation checkpoints and an error-recovery loop into the workflow, e.g. after inspecting the artifact ('only proceed to notarization analysis once the bundle structure validates') and after each prerequisite check ('if a nested framework is unsigned, fix and re-verify before continuing').

Include a short table or list of common failure signatures mapped to causes (e.g. 'nested code unsigned', 'hardened runtime not enabled', 'entitlement invalid') so the 'separate packaging issues from trust-policy symptoms' guidance is grounded in verifiable symptoms.

DimensionReasoningScore

Conciseness

The ~45-line body is lean with no padding and no explanations of concepts Claude already knows; every section (Quick Start, Workflow, Guardrails, Output Expectations) adds guidance only. Matches the 'every token earns its place' anchor.

5 / 5

Actionability

The workflow names concrete check categories ("nested frameworks, helper tools, and entitlements", "hardened runtime", "nested code signatures") but provides no executable commands (no codesign, spctl, xcrun notarytool, stapler) and even instructs to "Point to the minimum follow-up validation commands" without naming any. Guidance is concrete in structure but incomplete, matching anchor 3; the diagnostic skill is not destructive/batch so no lower cap applies.

3 / 5

Workflow Clarity

The four-step sequence (confirm goal, inspect artifact, inspect prerequisites, explain readiness) is coherent and well-ordered, but there are no validation checkpoints, no error-recovery loop, and step 4's 'minimum follow-up validation commands' is an instruction to reference validation rather than a checkpoint. Sequence present with checkpoints missing, matching anchor 3; it is not anchor 4 because validation gaps are not minor but absent.

3 / 5

Progressive Disclosure

The skill is under 50 lines, has no external references or bundle files, and its content needs none; sections are well-organized and self-contained, which per the rubric's simple-skill guideline earns a 5 on well-organized sections alone.

5 / 5

Total

16

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A well-formed description that clearly states both what the skill does and when to use it, in third person and without padding. Its main weaknesses are an abstract primary verb ('Prepare ... workflows') and trigger coverage that misses signing-related and file-extension terms users naturally say.

DimensionReasoningScore

Specificity

The description lists several concrete actions ("archiving apps, validating bundles, or explaining distribution-only failures"), but the core 'what' ("Prepare macOS packaging and notarization workflows") is abstract and omits signing/hardened runtime from the action list. It is above anchor 3 (more than 1-2 concrete actions) but below anchor 5 due to coverage gaps.

4 / 5

Completeness

Both a 'what' ("Prepare macOS packaging and notarization workflows") and an explicit 'when' clause with concrete triggers are present. Not anchor 5 because the 'what' is a single abstract action and the 'when' omits obvious signing/notarization-failure trigger phrasing; not anchor 3 because the 'when' is explicit, not weakly implied.

4 / 5

Trigger Term Quality

Natural trigger terms like "archiving apps", "notarization", "validating bundles", and "distribution" are present, but common synonyms and file extensions users would say (.app, .dmg, codesign, notarize, ship the app) are missing. Good coverage with a few natural terms absent, matching anchor 4.

4 / 5

Distinctiveness Conflict Risk

"macOS packaging and notarization" with "distribution-only failures" defines a clear niche with distinct triggers and minimal conflict risk with other skills. Only trivial overlap with a hypothetical general code-signing skill.

5 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
robinebers/openusage
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.