By gaelic-ghost
Security analysis, incident response, and defensive workflow skills.
Decode and analyze suspicious scripts and active documents without triggering them. Use for shell, AppleScript, JavaScript, Python, PowerShell, shortcuts, Office files, PDFs, configuration profiles, encoded commands, macros, embedded objects, external templates, staged downloads, or mixed document-to-script payload chains.
Assess whether suspicious evidence indicates a real threat and explain the result in practical language. Use when a person needs a confidence-calibrated conclusion, immediate protective actions, remaining uncertainty, impact, or understandable advice after artifact, endpoint, vulnerability, identity, or incident evidence has been collected.
Prioritize a validated or plausible vulnerability using actual asset exposure and impact. Use when affected versions, deployment reachability, attacker prerequisites, privileges, sensitive data, exploit maturity, CISA KEV status, vendor guidance, mitigations, detection, business criticality, CVSS, and remediation urgency must be combined without relying on a severity score alone.
Assess a suspected macOS security threat using exact host, artifact, and platform evidence. Use for suspicious apps, packages, processes, prompts, downloads, profiles, extensions, XProtect or Gatekeeper alerts, account behavior, persistence, privacy access, or unexpected network activity when signing, notarization, quarantine, TCC, SIP, and observed behavior must remain distinct.
Turn validated security behavior into tested detection content. Use for Sigma, osquery, YARA-X routing, endpoint queries, SIEM rules, cloud or application detections, correlation logic, alert enrichment, or regression fixtures when telemetry prerequisites, provenance, expected matches, benign negatives, false-positive controls, performance, severity, response, deployment, and maintenance ownership must be explicit.
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
The macOS Marketplace for Codex


Promo audio: Socket Codex Marketplace Promo
socket is maintained by Gaelic Ghost.
Socket is a Marketplace of Plugins, Hooks, and MCP servers for Apple Platform Devs
Agents are great, but to do specialized work, they need specialized tools. Socket is a shared catalog for focused Codex plugins, hooks, skills, and MCP-backed workflows.
Add the socket marketplace to Codex with:
codex plugin marketplace add gaelic-ghost/socket
After adding socket, restart your Codex, open the plugin directory, select Socket, and then install your choice of plugins.
When the marketplace changes, refresh it with:
codex plugin marketplace upgrade socket
Newly added plugins can be installed from the same plugin directory inside Codex.
Socket publishes an explicit Hermes compatibility surface for portable skills and translated MCP configuration:
hermes skills tap add gaelic-ghost/socket
hermes skills install gaelic-ghost/socket/hermes-agent-compatibility
Codex plugin bundles remain host-specific. See the Hermes compatibility guide for the available skill tap, MCP translations, and the cases that need a native Hermes plugin.
Socket also publishes a Claude marketplace. In Claude Code, add it with:
claude plugin marketplace add gaelic-ghost/socket
Then install the individual Socket plugins you want. Cowork users can add the same GitHub marketplace from Customize → Plugins. Socket skills work in both hosts; local Mac integrations such as Xcode, Cardhop, and Things are Claude Code-only. Speak Swiftly remains unavailable in this catalog until its standalone payload has a Claude-native hook boundary. See the Claude compatibility guide for the full support boundary and update flow.
For Xcode 27 beta, add Socket through Xcode's official Plug-ins UI:
https://github.com/gaelic-ghost/socket.git
Xcode should enumerate the Socket child plug-ins from the public repository and let you import only the plug-ins you trust and need.
The Import from Codex path is still under evaluation for Xcode 27 beta. In current local testing, Xcode can see Codex-installed plug-ins, but it may select stale standalone or local-cache payloads when the same plug-in also exists outside the current Socket marketplace install. Prefer Add from URL for Socket until that beta behavior is better understood.
For Zed's Codex external agent, install and update Socket through the normal Codex marketplace flow. Current local testing shows Zed's bundled codex-acp path inherits the user's normal Codex home by default, so Codex-in-Zed sees the same global ~/.codex config, Socket marketplace cache, installed plug-ins, skills, and MCP servers as the regular Codex CLI and GUI unless Zed or the adapter is launched with an explicit CODEX_HOME.
Zed's own first-party Agent uses Zed-native skills and MCP configuration. Treat that as a separate compatibility surface from Codex running inside Zed through ACP.
Use socket when you want one Codex catalog for focused agent workflow plugins.
Currently available from the catalog:
agent-portability-skillsandroid-dev-skillsapple-creator-studio-skillsapple-dev-skillscardhop-appcloud-deployment-skillscloud-inference-skillscybersecurity-skillsmessaging-collaboration-skillsmodel-lab-skillsagentdeckdotnet-skillsgame-dev-skillsnetwork-protocol-skillsproductivity-skillspython-skillsreverse-engineering-skillsserver-side-jvmserver-side-swiftswift-langrust-skillsspeak-swiftlyswiftasb-skillsthings-appweb-dev-skillsApple Dev Skills is Socket-owned under plugins/apple-dev-skills and keeps its public README because existing users can still arrive through the standalone compatibility marketplace. Other child planning now lives in ROADMAP.md.
Current Socket catalog shape:
npx claudepluginhub gaelic-ghost/socket --plugin cybersecurity-skillsSwiftASB integration and application-development workflows.
Android, Kotlin, Java, Gradle, testing, and release workflows.
Apple game-development workflows for Metal, SpriteKit, SceneKit, and gameplay systems.
Maintainer, documentation, job-search, and automation-design workflows.
Cross-host agent-skill and plugin portability workflows.
Harness-native ECC plugin for engineering teams - 67 agents, 279 skills, 94 legacy command shims, reusable hooks, rules, MCP conventions, and operator workflows for Claude Code plus adjacent agent harnesses
Comprehensive skill pack with 66 specialized skills for full-stack developers: 12 language experts (Python, TypeScript, Go, Rust, C++, Swift, Kotlin, C#, PHP, Java, SQL, JavaScript), 10 backend frameworks, 6 frontend/mobile, plus infrastructure, DevOps, security, and testing. Features progressive disclosure architecture for 50% faster loading.
A growing collection of Claude-compatible academic workflow bundles. Covers scientific figures, manuscript writing and polishing, reviewer assessment, citation retrieval, data availability, paper reading, literature search, response letters, paper-to-PPTX conversion, and evidence-grounded Chinese invention patent drafting. Rules are organized as reusable skill folders with explicit workflows and quality checks.
Core skills library for Claude Code: TDD, debugging, collaboration patterns, and proven techniques
Plugin-safe Claude Code distribution of Agentic Awesome Skills with 1,933 supported skills.
This skill should be used when users need to generate ideas, explore creative solutions, or systematically brainstorm approaches to problems. Use when users request help with ideation, content planning, product features, marketing campaigns, strategic planning, creative writing, or any task requiring structured idea generation. The skill provides 30+ research-validated prompt patterns across 14 categories with exact templates, success metrics, and domain-specific applications.