From cybersecurity-skills
Assess a suspected macOS security threat using exact host, artifact, and platform evidence. Use for suspicious apps, packages, processes, prompts, downloads, profiles, extensions, XProtect or Gatekeeper alerts, account behavior, persistence, privacy access, or unexpected network activity when signing, notarization, quarantine, TCC, SIP, and observed behavior must remain distinct.
How this skill is triggered — by the user, by Claude, or both
Slash command
/cybersecurity-skills:assess-macos-threatThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
Establish the affected Mac and event timeline before changing the system. Use Apple security layers as separate evidence sources and route focused persistence, runtime, artifact, or containment work from the resulting record.
Establish the affected Mac and event timeline before changing the system. Use Apple security layers as separate evidence sources and route focused persistence, runtime, artifact, or containment work from the resulting record.
Read references/macos-security-layers.md when interpreting platform controls or alerts.
macos-privacy-permissions-workflow; route private symbols, control internals, or exact-build Gatekeeper/XProtect/TCC questions to research-macos-security-control.Return host/event identity, platform-layer evidence, artifact identity, observed behavior, assessment/confidence, immediate advice, and focused next checks.
Do not interpret an XProtect or Gatekeeper event alone as proof that malware executed or that the host is compromised. Preserve the event type, exact OS/security-data state, actor/artifact identity, and observed behavior.
npx claudepluginhub gaelic-ghost/socket --plugin cybersecurity-skillsCreates, edits, and verifies skills using a test-driven development approach with pressure scenarios and subagents.