Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add gaelic-ghost/socketnpx agentmods add plugins/gaelic-ghost/socket/apple-dev-skillsgit clone --depth 1 https://github.com/gaelic-ghost/socketWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/gaelic-ghost/socket/apple-dev-skills)<a href="https://agentmods.dev/plugins/gaelic-ghost/socket/apple-dev-skills"><img src="https://agentmods.dev/badge/plugins/gaelic-ghost/socket/apple-dev-skills.svg" alt="Measured on agentmods" height="20"></a>Grade A, and why
apple-dev-skills scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "apple-dev-skills",
"source": "./plugins/apple-dev-skills",
"description": "Apple, SwiftPM, Xcode, macOS privacy, file access, entitlement, and virtualization workflows.",
"category": "developer-tools",
"tags": [
"apple",
"swift",
"swiftpm",
"xcode",
"macos",
"privacy",
"entitlements",
"virtualization"
],
"mcpServers": "./.mcp.json",
"strict": false
}What it installs
The manifest is a name and a version. 65 skills, 2 MCP servers travel with it, and installing the plugin installs all of them — 4,741 tokens a session between them. Each is measured on its own page, and each can be installed alone.
- Skill icon-composer-app-icon-workflow A 73 tokens
- Skill bootstrap-xcode-workspace A 36 tokens
- Skill appkit-app-architecture-workflow A 86 tokens
- Skill apple-developer-provisioning-workflow A 85 tokens
- Skill devicecheck-app-attest-workflow A 126 tokens
- Skill safari-extension-control-workflow A 91 tokens
- Skill swiftui-app-architecture-workflow A 88 tokens
- Skill xcode-coding-intelligence-workflow A 49 tokens
- Skill xcode-localization-workflow A 69 tokens
- Skill xcode-testing-workflow A 81 tokens
- Skill app-extension-architecture-workflow A 49 tokens
- Skill core-animation-layer-workflow A 143 tokens
- Skill explore-apple-swift-docs A 78 tokens
- Skill format-swift-sources A 74 tokens
- Skill sf-symbols-workflow A 109 tokens
- Skill swift-openapi-client-workflow A 73 tokens
- Skill swift-package-build-run-workflow A 62 tokens
- Skill swift-package-testing-workflow A 77 tokens
- Skill swiftui-animation-workflow A 112 tokens
- Skill xcode-build-run-workflow A 67 tokens
- Skill apple-typography-workflow A 145 tokens
- Skill apple-ui-accessibility-workflow A 76 tokens
- Skill avaudio-engine-workflow A 77 tokens
- Skill avfaudio-session-workflow A 84 tokens
- Skill avfoundation-media-pipeline-workflow A 82 tokens
- Skill camera-capture-depth-workflow A 87 tokens
- Skill coreaudio-modernization-repair-workflow A 82 tokens
- Skill coremedia-timing-samplebuffer-workflow A 90 tokens
- Skill file-provider-and-finder-sync-workflow A 45 tokens
- Skill mailkit-workflow A 48 tokens
- Skill photos-library-editing-workflow A 91 tokens
- Skill structure-swift-sources A 69 tokens
- Skill swift-package-extension-workflow A 46 tokens
- Skill swiftui-component-audit-workflow A 65 tokens
- Skill tvos-app-experience-workflow A 53 tokens
- Skill tvos-media-playback-workflow A 52 tokens
- Skill video-codec-processing-workflow A 83 tokens
- Skill app-intents-workflow A 59 tokens
- Skill apple-image-representation-workflow A 81 tokens
- Skill arkit-face-body-tracking-workflow A 82 tokens
- Skill arkit-spatial-sensing-workflow A 81 tokens
- Skill author-swift-docc-docs A 70 tokens
- Skill core-image-processing-workflow A 74 tokens
- Skill diagnose-apple-entitlements A 51 tokens
- Skill linux-development-vm-workflow A 54 tokens
- Skill macos-privacy-permissions-workflow A 54 tokens
- Skill macos-sandbox-file-access-workflow A 61 tokens
- Skill safari-mcp-workflow A 48 tokens
- Skill swiftui-liquid-glass A 55 tokens
- Skill tipkit-workflow A 109 tokens
- Skill vision-coreml-recognition-workflow A 74 tokens
- Skill vision-image-analysis-workflow A 79 tokens
- Skill xcode-debugger-mcp-workflow A 70 tokens
- Skill xcode-device-hub-workflow A 54 tokens
- Skill choose-macos-virtualization-shape A 54 tokens
- Skill feedback-assistant-workflow A 87 tokens
- Skill ios-runtime-forensics-workflow A 54 tokens
- Skill macos-development-vm-workflow A 48 tokens
- Skill macos-distribution-workflow A 53 tokens
- Skill swiftdata-workflow A 74 tokens
- Skill swiftui-performance-audit A 61 tokens
- Skill tips-helpviewer-workflow A 93 tokens
- Skill virtualization-framework-workflow A 49 tokens
- Skill apple-runtime-telemetry-workflow A 55 tokens
- Skill macos-window-management-workflow A 54 tokens
- MCP server xcode A not measured
- MCP server xcode_lldb A not measured
What ships with it
1 file beside marketplace.json#apple-dev-skills in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 18 lines scan A 9ba931c45e47
apple-dev-skills is a plugin published in the GitHub repository gaelic-ghost/socket (7 stars, last pushed 9d ago), licensed Apache-2.0. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other plugins, from other repositories
deploygate
DeployGate agent integration: upload mobile apps, manage distribution pages, set up CI/CD, and onboard your team. Supports iOS (IPA) and Android (APK/AAB).
superb
Personal skill collection. Skills are invoked as superb: . craft turns a vague product idea into a decision-rich CRAFT.md brief — it questions, challenges and records, and deliberately stops short of planning. pipeline takes a settled idea to a finished branch, composing the superpowers skills with a zero-assumpt.
setup-vscode-swift
Set up VS Code for Swift and Xcode projects on macOS with SweetPad, Swift extensions, shortcuts, and buildServer.json.
apple-engineer-superpowers
Apple platform engineering skill for Claude Code: Swift 6 concurrency, SwiftUI, Metal GPU, RealityKit, visionOS, and advanced patterns.
cadence
A plan/execute/verify loop for a single developer in Claude Code, with adversarial review at every gate: plans and diffs get refuted by a fresh Claude subagent or a panel of outside models (OpenAI, Gemini, DeepSeek), not just approved. State lives in files, not the conversation, so you clear aggressively and keep both.
compose-expert
Compose and Compose Multiplatform expert skill — state, animations, navigation, performance, design-to-code, PR review mode, M3 motion.