axiom-app-attest

axiom-app-attest is a skill for Claude Code, Codex from ComeOnOliver/skillshub. It costs 63 tokens per session (3,593 once invoked), scanned A, original, MIT.

A guide to Apple’s App Attest and DeviceCheck systems, which let a server check that requests come from an unmodified copy of your iOS app on a genuine Apple device.

In plain words
What is it for?
It helps implement key generation, app attestation, request assertions, server-side signature checks, DeviceCheck state, and gradual rollout.
Why use it?
It helps reduce fraud from cloned or modified apps and repeated promotional claims by verifying app requests on the server.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one.

Good fit It helps implement key generation, app attestation, request assertions, server-side signature checks, DeviceCheck state, and gradual rollout.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/comeonoliver/skillshub/axiom-app-attest
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add ComeOnOliver/skillshub --skill axiom-app-attest
Clone the repo
git clone --depth 1 https://github.com/ComeOnOliver/skillshub

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for axiom-app-attest

README.md
[![agentmods](https://agentmods.dev/badge/skills/comeonoliver/skillshub/axiom-app-attest/github.svg)](https://agentmods.dev/skills/comeonoliver/skillshub/axiom-app-attest)
Your own site
<a href="https://agentmods.dev/skills/comeonoliver/skillshub/axiom-app-attest"><img src="https://agentmods.dev/badge/skills/comeonoliver/skillshub/axiom-app-attest/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for axiom-app-attest

Your own site · 80×15
<a href="https://agentmods.dev/skills/comeonoliver/skillshub/axiom-app-attest"><img src="https://agentmods.dev/badge/skills/comeonoliver/skillshub/axiom-app-attest.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 63 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 3,593 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00063 $0.03593
Opus 5 $0.00032 $0.01796
Sonnet 5 $0.00013 $0.00719
Haiku 4.5 $0.00006 $0.00359

Measured 9d ago against content hash 303e257bfa9b, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

axiom-app-attest scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/CharlesWiltgen/Axiom/axiom-app-attest/SKILL.md · 336 lines

How it starts

The opening of the file, as written. The whole thing — 336 lines — stays where its author put it; the contents beside it link to each section on GitHub.

App Attest

Device-backed app integrity verification for fraud prevention. Proves three things to your server: the request came from a genuine Apple device, running your genuine app, with an untampered payload.

When to Use This Skill

Use when you need to:

  • Verify requests come from legitimate app instances (not modified/cloned apps)
  • Prevent fraud in purchases, promotions, or competitive features
  • Implement DCAppAttestService attestation or assertion flows
  • Handle DeviceCheck 2-bit per-device state for promotional abuse
  • Build server-side validation for attestation objects or assertion signatures
  • Plan a gradual App Attest rollout for a large install base

Example Prompts

"How do I verify my app hasn't been tampered with?" "DCAppAttestService attestKey keeps failing with serverUnavailable" "How do I prevent users from claiming a free trial multiple times?" "What's the difference between attestation and assertion?" "How do I validate an attestation object on my server?" "isSupported returns false — should I block the user?" "We have 2M DAU, how do I roll out App Attest safely?" "How do I detect if someone is creating fake app instances?"

Red Flags

Signs you're headed for trouble:

  • Validating app integrity on-device — Modified apps control the runtime. Any local check can be patched out. Verification MUST happen server-side.
  • Not guarding with isSupported — DCAppAttestService crashes on unsupported devices. Always check before calling any API.
  • Blocking users when isSupported returns false — Some legitimate devices return false. Treat as risk signal, not hard block.
  • Reusing keys across multiple users on same device — One key per user per device. Shared keys break account-level trust association.
  • Enabling App Attest for all users at onceattestKey calls Apple's servers. At scale, rate limiting causes failures. Gradual rollout required (WWDC 2021-10244).
  • Using assertions for every API call — Cryptographic cost per call. Reserve for sensitive operations (purchases, account changes), not routine fetches.
  • Discarding key on serverUnavailable error — Transient Apple server issue. Retry with same key. Only discard on other errors.
  • Skipping counter validation on server — Counter must be ever-increasing. Without this, replay attacks succeed.

Read the full file on GitHub · 336 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 9d ago First seen · 336 lines · 63 tokens per session scan A 303e257bfa9b

Subscribe to this mod's changes

axiom-app-attest is a skill published in the GitHub repository ComeOnOliver/skillshub (63 stars, last pushed 2mo ago), licensed MIT. It adds 63 tokens to every session and 3,593 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.