CtrlK
BlogDocsLog inGet started
Tessl Logo

packaging-notarization

Prepare and troubleshoot packaging, signing, and notarization workflows for macOS distribution. Use when asked to archive a Mac app, validate bundle structure, reason about notarization readiness, or explain distribution-only failures.

70

Quality

85%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

The canonical home for this skill is packaging-notarization in openai/plugins

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A lean, well-structured instruction-only skill with a clear workflow and guardrails, but its guidance stays at the checklist level: it names what to verify (hardened runtime, nested signatures, entitlements) without a single concrete command to verify it with. Adding the minimal validation commands it already points to would lift actionability substantially.

Suggestions

Include the concrete validation commands the workflow references, e.g. `codesign --verify --deep --strict <app>`, `spctl -a -v <app>`, `stapler validate <app>`, and `xcrun notarytool history`.

Add an explicit validate→fix→retry checkpoint in the workflow (e.g. after inspecting signing prerequisites, re-verify before declaring readiness).

Show how to inspect bundle structure and entitlements concretely (e.g. `codesign -d --entitlements -` or checking Frameworks/ and Helpers/ layout) instead of the bare instruction "Validate app bundle structure".

DimensionReasoningScore

Conciseness

The 43-line body is lean across four tight sections with no explanation of concepts Claude already knows and no padding; the Quick Start line "Use this skill when the work is about shipping the app rather than merely running it locally" earns its place by scoping the skill. Every token pulls weight, matching the "lean and efficient; assumes Claude's competence" anchor.

5 / 5

Actionability

The checklist items are concrete ("Hardened runtime", "Signing identity", "Nested code signatures", "Required entitlements") but no executable command appears anywhere — no `codesign --verify --deep`, `spctl -a -v`, `stapler validate`, or `xcrun notarytool` — even though the workflow says "Point to the minimum follow-up validation commands". The instruction-only exemption from the code requirement doesn't fully apply because the how-to-execute detail is missing, fitting "some concrete guidance but incomplete; missing key details" rather than the mostly-executable anchor above.

3 / 5

Workflow Clarity

The four-step sequence (confirm goal → inspect artifact → inspect signing/runtime prerequisites → explain readiness) is clearly ordered and domain-appropriate, with validation present but implicit ("Validate app bundle structure" and the output expectation of "the next validation or repair step"). This matches "clear sequence with most checkpoints present; minor validation gaps"; it lacks the explicit validate→fix→retry loop of the top anchor, though no destructive/batch cap applies.

4 / 5

Progressive Disclosure

The skill is under 50 lines, has no bundle files (no references/, scripts/, or assets/ exist), and nothing inlined belongs in a separate file; well-organized sections with clear headers are sufficient for a skill of this size per the simple-skill guidance.

5 / 5

Total

17

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: third-person voice, explicit what-and-when, and concrete trigger phrases tied to a well-defined macOS distribution niche. The only gap is keyword coverage — a few natural synonyms and file extensions users would actually say are absent.

Suggestions

Add natural trigger synonyms users would say verbatim, e.g. "notarize", "codesign", ".app bundle", or "dmg".

Consider mentioning the staple/upload step (e.g. "staple a notarization ticket") since it is a common user phrasing in this workflow.

DimensionReasoningScore

Specificity

"Prepare and troubleshoot packaging, signing, and notarization workflows for macOS distribution" plus "archive a Mac app, validate bundle structure, reason about notarization readiness, or explain distribution-only failures" names the domain and multiple concrete actions with comprehensive coverage of both preparation and troubleshooting paths, matching the anchor for several specific concrete actions without coverage gaps.

5 / 5

Completeness

It explicitly answers what ("Prepare and troubleshoot packaging, signing, and notarization workflows for macOS distribution") and when ("Use when asked to archive a Mac app, validate bundle structure, reason about notarization readiness, or explain distribution-only failures") with concrete trigger phrases, matching the top anchor.

5 / 5

Trigger Term Quality

Natural phrases like "archive a Mac app", "notarization readiness", and "macOS distribution" are present and users would plausibly say them, but common variations and synonyms are missing — e.g. the verb form "notarize", "codesign", ".app", or "dmg" — so it fits "good keyword coverage; a few natural terms missing" rather than comprehensive coverage.

4 / 5

Distinctiveness Conflict Risk

macOS packaging/notarization is a clear niche with distinct triggers, and "distribution-only failures" explicitly carves scope apart from local-build skills; "signing" alone is mildly broad but "notarization" and "macOS distribution" keep conflict risk minimal.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
robinebers/openusage
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.