{"id":24668,"plugin_id":"plugins~Plugin_b80dd84519148191a409cde181c9b3d6","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:18:34.415Z","digest":"19885df33da26efef2088de3ad3b358378ce004cfca9e68b31326d24c2af9273","against":null,"payload":{"name":"signing-entitlements","description":"Inspect macOS signing, entitlements, and Gatekeeper issues. Use when diagnosing code signing, sandbox, hardened runtime, or trust failures.","included_files":[{"relative_path":"agents/openai.yaml","size_in_bytes":290}],"skill_md_contents":"---\nname: signing-entitlements\ndescription: Inspect macOS signing, entitlements, and Gatekeeper issues. Use when diagnosing code signing, sandbox, hardened runtime, or trust failures.\n---\n\n# Signing & Entitlements\n\n## Quick Start\n\nUse this skill when the failure smells like codesigning rather than compilation:\nlaunch refusal, missing entitlement, invalid signature, sandbox mismatch,\nhardened runtime confusion, or trust-policy rejection.\n\n## Workflow\n\n1. Inspect the bundle or binary.\n   - Locate the `.app` or executable.\n   - Identify the main binary inside `Contents/MacOS/`.\n\n2. Read signing details.\n   - Use `codesign -dvvv --entitlements :- <path>`.\n   - Use `spctl -a -vv <path>` when Gatekeeper behavior matters.\n   - Use `plutil -p` for entitlements or Info.plist inspection.\n\n3. Classify the failure.\n   - Unsigned or ad hoc signed\n   - Wrong identity\n   - Entitlement mismatch\n   - Hardened runtime issue\n   - App Sandbox issue\n   - Nested code signing issue\n   - Distribution/notarization prerequisite issue\n\n4. Explain the minimum fix path.\n   - Say exactly what is wrong.\n   - Show the shortest set of validation or repair commands.\n   - Distinguish local development problems from distribution problems.\n\n## Useful Commands\n\n- `codesign -dvvv --entitlements :- <app-or-binary>`\n- `spctl -a -vv <app-or-binary>`\n- `security find-identity -p codesigning -v`\n- `plutil -p <path-to-entitlements-or-plist>`\n\n## Guardrails\n\n- Never invent missing entitlements.\n- Do not conflate notarization with local debug signing.\n- If the real issue is a build setting or provisioning profile, say so directly.\n\n## Output Expectations\n\nProvide:\n- what artifact was inspected\n- what signing state it is in\n- the exact failure class\n- the minimum fix or validation sequence\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}