app-extension-architecture-workflow

app-extension-architecture-workflow is a skill for Claude Code, Codex from gaelic-ghost/socket. It costs 49 tokens per session (2,165 once invoked), scanned A, original, Apache-2.0.

A guide for planning Apple app extensions, which are separate app components that run alongside a main app and provide focused system features.

In plain words
What is it for?
Use it to plan extension points, communication between the app and extension, shared containers, privacy, testing, signing, and distribution.
Why use it?
It helps resolve which extension type, app target, permissions, data sharing, and security boundaries are needed before implementation.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/gaelic-ghost/socket/app-extension-architecture-workflow
Any agent
npx skills add gaelic-ghost/socket --skill app-extension-architecture-workflow
Clone the repo
git clone --depth 1 https://github.com/gaelic-ghost/socket

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for app-extension-architecture-workflow

README.md
[![agentmods](https://agentmods.dev/badge/skills/gaelic-ghost/socket/app-extension-architecture-workflow.svg)](https://agentmods.dev/skills/gaelic-ghost/socket/app-extension-architecture-workflow)
Your own site
<a href="https://agentmods.dev/skills/gaelic-ghost/socket/app-extension-architecture-workflow"><img src="https://agentmods.dev/badge/skills/gaelic-ghost/socket/app-extension-architecture-workflow.svg" alt="Measured on agentmods" height="20"></a>
Per session 49 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,165 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00049 $0.02165
Opus 5 $0.00024 $0.01082
Sonnet 5 $0.00010 $0.00433
Haiku 4.5 $0.00005 $0.00216

Measured 4d ago against content hash f700ed48d397, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

app-extension-architecture-workflow scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/apple-dev-skills/skills/app-extension-architecture-workflow/SKILL.md · 141 lines

How it starts

The opening of the file, as written. The whole thing — 141 lines — stays where its author put it; the contents beside it link to each section on GitHub.

App Extension Architecture Workflow

Purpose

Choose and structure an Apple app extension before implementation. Apple documents app extensions as separate bundles whose code runs in a separate process; the extension point and host define the lifecycle, APIs, and activation contract. This skill owns those reusable mechanics, not product-specific framework behavior.

It owns extension-point routing, target and process boundaries, activation, entitlements, app groups and shared containers, bounded data flow, privacy, testing, signing, and distribution. It does not absorb MailKit, File Provider, Finder Sync, Safari, Messages/iMessage, communication-notification, VoIP, Push to Talk, widget, intent, or other product-framework guidance.

When To Use

  • Use this skill when a request needs an Apple app extension but the right extension point, host relationship, or target structure is unclear.
  • Use this skill when planning a containing app and extension targets, process isolation, activation, app groups, shared containers, XPC, privacy boundaries, signing, or distribution.
  • Use mailkit-workflow for macOS Mail content blocking, message actions, compose sessions, or message security.
  • Use file-provider-and-finder-sync-workflow for remote storage synchronization or Finder badges, menus, and monitored-folder visibility.
  • Use safari-extension-control-workflow for Safari-specific extension and SafariServices choices.
  • Use Messaging Collaboration Skills for Messages/iMessage collaboration, communication-notification policy, VoIP, or Push to Talk workflows.
  • Recommend explore-apple-swift-docs when the immediate need is current Apple documentation for a named extension point.
  • Recommend xcode-build-run-workflow or xcode-testing-workflow when target execution or test mechanics are the next step.

Single-Path Workflow

  1. Classify the extension point and host:
    • name the system host, supported platform, activation trigger, user-visible configuration, and expected lifetime
    • choose an existing Apple extension point and its documented template or contract; do not invent a generic extension target
    • route product behavior to its dedicated workflow before designing shared mechanics
  2. State the documented behavior relied on:
    • app extensions are separate bundles that run in separate processes
    • the host controls activation and the extension-point API contract
    • use the extension point’s APIs and lifecycle rather than assuming the containing app is running or reachable
    • stop and surface a conflict if current code assumes a lifecycle, privilege, or data access that Apple documentation does not support
  3. Design targets and ownership:
    • give the containing app, each extension target, and any shared framework or package one clear job
    • in the canonical product workspace, place every extension target directly at Apps/<ExtensionTarget>/ as a peer of its containing app and test targets; never create a root Extensions/ tree
    • require the containing app's XcodeGen target dependency to name and embed the extension explicitly; directory proximity or target naming is not host evidence
    • keep extension entry points thin; put portable domain logic in deliberately shared source only when both targets need it
    • do not use a shared target to smuggle UI, host-only state, or privileged access across process boundaries
  4. Define the process and data-flow contract:
    • state where each operation runs, how work is activated, what happens when the host interrupts or relaunches it, and what can be retried safely
    • prefer the extension point’s documented request, completion, and cancellation APIs
    • use XPC only where the extension-point contract or a documented app-extension API actually supports it
    • make payload types small, typed, versioned when persisted, and free of secrets unless the secure storage and access policy is explicit
  5. Minimize entitlements and shared state:
    • grant each target only the capabilities it needs
    • use an App Group only when the app and extension genuinely need a shared container or documented IPC support
    • validate membership in every participating target; on macOS, test actual container access rather than trusting a returned URL alone
    • do not treat an App Group as a general cross-process database, privilege escalation path, or substitute for an extension-point API
  6. Plan privacy and failure behavior:
    • inventory data read by the host, extension, and shared container separately
    • retain the minimum data for the minimum time, avoid sensitive logs, and make user-facing effects explainable
    • define cancellation, timeout, unavailable-host, disabled-extension, migration, and stale-shared-state behavior before shipping
  7. Plan validation and distribution:
    • validate target membership, Info.plist extension-point configuration, entitlements, signing, embedding, install/enable state, activation, and clean-device behavior
    • test the extension independently where its framework permits; extract pure/shared logic into a testable target instead of trying to unit-test an unsupported extension process directly
    • validate the same signing and distribution path intended for users; do not infer App Store, notarization, or enterprise behavior from a development build
  8. Return one recommendation with the extension point, target map, lifecycle/data-flow boundary, entitlement/share plan, privacy plan, validation sequence, and the next focused handoff.
  9. Hand settled target creation or existing-target adoption to bootstrap-xcode-workspace --operation add-component|adopt; this workflow chooses the extension contract while the workspace workflow owns placement, XcodeGen registration, host embedding, and the permanent project graph.

Read the full file on GitHub · 141 lines

Files

What ships with it

5 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 141 lines · 49 tokens per session scan A f700ed48d397

Subscribe to this mod's changes

app-extension-architecture-workflow is a skill published in the GitHub repository gaelic-ghost/socket (7 stars, last pushed 8d ago), licensed Apache-2.0. It adds 49 tokens to every session and 2,165 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

pipeline

Use when the user wants a feature idea taken end-to-end in one autonomous run — phrases like "run the whole pipeline", "take this feature from idea to finished branch", "brainstorm then build it autonomously", "do everything from idea to merged", "implement all phases without stopping". Triggers when they want…

kardebadas/claude-plugin · 80 tokens

craft

Use when a product idea is still vague and needs to become a clear definition of what to build — "let's craft an app like X", "help me define what I actually want", "clarify this idea before we plan it". Also use before planning or implementation when requirements, UX, domain behaviour, or technical preferences have…

kardebadas/claude-plugin · 83 tokens

implement-factory

Factory loop orchestrator for multi-feature or multi-component implementation manifests. Use for high-complexity work with parallel-eligible workstreams and holdout-scenario evaluation.

rsmdt/the-startup · 37 tokens

scenario-planning

Plans under genuine uncertainty — building scenarios, identifying which assumptions are load-bearing, setting early-warning indicators, and stress-testing a plan against futures rather than forecasting one. Use this when a decision depends on something unknowable, when a plan assumes conditions that may not hold…

cbrock84/headcount · 78 tokens

ai-ml-governance

Governs models and AI systems in production — intended use, evaluation, monitoring, human oversight, documentation, and the decision to deploy or retire. Use this before deploying a model or AI feature, when defining evaluation criteria, when a model's behavior has drifted, when assessing AI risk or regulatory…

cbrock84/headcount · 83 tokens

ai-research-analyst

Produces executive-level research — market sizing, competitor mapping, trend analysis, and strategic intelligence — grounded in cited sources with the confidence in each claim made explicit. Use this to analyze a market or industry, map competitors, evaluate a market-entry or build-versus-buy decision, produce a…

cbrock84/headcount · 91 tokens