CtrlK
BlogDocsLog inGet started
Tessl Logo

macos-signing-entitlements

Inspect macOS signing, entitlements, and Gatekeeper issues. Use when diagnosing code signing, sandbox, hardened runtime, or trust failures.

67

Quality

80%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

The canonical home for this skill is signing-entitlements in openai/plugins

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A lean, well-structured diagnostic skill with concrete, executable inspection commands and a clear classification workflow. The main gaps are minor duplication between sections and the absence of distinguishing criteria or example fix commands for the enumerated failure classes.

Suggestions

Drop the duplicated commands from 'Useful Commands' or from Workflow step 2 so each appears once.

Add a one-line distinguishing signal for the failure classes in step 3 (e.g., which Authority/TeamIdentifier or entitlement output indicates each class).

Include one example repair command (e.g., an ad-hoc re-sign for local development) to make step 4's fix path concrete.

DimensionReasoningScore

Conciseness

The body is lean with no concept explanations Claude already knows, but 'Useful Commands' duplicates two commands (`codesign -dvvv`, `spctl -a -vv`) already shown in Workflow step 2, and Quick Start partly restates the frontmatter description.

4 / 5

Actionability

Concrete copy-paste-ready commands (`codesign -dvvv --entitlements :-`, `spctl -a -vv`, `plutil -p`, `security find-identity`) are provided, but no example repair/re-sign command accompanies step 4's request for 'repair commands', and the seven failure classes lack distinguishing criteria.

4 / 5

Workflow Clarity

The four-step sequence (locate binary, read signing details with specific commands, classify, explain fix) is clear and operations are read-only so no validation cap applies, but there is no feedback loop for ambiguous classifications or for verifying a fix worked.

4 / 5

Progressive Disclosure

This is a short (~54 lines), single-purpose skill with well-organized sections (Quick Start, Workflow, Useful Commands, Guardrails, Output Expectations) and no need for external reference files, satisfying the simple-skill exception for a top score.

5 / 5

Total

17

/

20

Passed

Description

82%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description with an explicit 'Use when' clause, good natural trigger terms, and a clearly distinct macOS niche. Its main weakness is limited enumeration of concrete capabilities beyond the single 'Inspect' action.

Suggestions

Add one or two more concrete action verbs to the what-clause (e.g., 'Inspect ... and classify failures as signing, entitlement, sandbox, or notarization problems').

Include commonly used trigger terms such as 'notarization', 'codesign', or 'provisioning profile' to broaden natural keyword coverage.

DimensionReasoningScore

Specificity

The description names the domain ('macOS signing, entitlements, and Gatekeeper issues') but relies on a single action verb ('Inspect') without listing several concrete capabilities, matching the 'domain plus 1-2 concrete actions' anchor rather than the comprehensive multi-action anchor.

3 / 5

Completeness

It explicitly answers both what ('Inspect macOS signing, entitlements, and Gatekeeper issues') and when ('Use when diagnosing code signing, sandbox, hardened runtime, or trust failures') with concrete trigger phrases, matching the top anchor.

5 / 5

Trigger Term Quality

Natural trigger terms like 'code signing', 'sandbox', 'hardened runtime', 'Gatekeeper', and 'trust failures' are present, but common user phrases such as 'notarization', 'codesign', and 'provisioning' are missing.

4 / 5

Distinctiveness Conflict Risk

The macOS-specific signing/entitlements niche with distinct technical triggers ('Gatekeeper', 'hardened runtime', 'sandbox') makes conflict with other skills minimal.

5 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
robinebers/openusage
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.