signing-entitlements

โดย openai

ตรวจสอบปัญหาเกี่ยวกับการลงนาม การอนุญาต รันไทม์ที่แข็งแกร่ง และ Gatekeeper สำหรับแอป macOS ใช้เมื่อถูกขอให้วินิจฉัยความล้มเหลวในการลงนามโค้ด การอนุญาตที่ขาดหายไป…

npx skills add https://github.com/openai/plugins --skill signing-entitlements

Signing & Entitlements

Quick Start

Use this skill when the failure smells like codesigning rather than compilation: launch refusal, missing entitlement, invalid signature, sandbox mismatch, hardened runtime confusion, or trust-policy rejection.

Workflow

  1. Inspect the bundle or binary.

    • Locate the .app or executable.
    • Identify the main binary inside Contents/MacOS/.
  2. Read signing details.

    • Use codesign -dvvv --entitlements :- <path>.
    • Use spctl -a -vv <path> when Gatekeeper behavior matters.
    • Use plutil -p for entitlements or Info.plist inspection.
  3. Classify the failure.

    • Unsigned or ad hoc signed
    • Wrong identity
    • Entitlement mismatch
    • Hardened runtime issue
    • App Sandbox issue
    • Nested code signing issue
    • Distribution/notarization prerequisite issue
  4. Explain the minimum fix path.

    • Say exactly what is wrong.
    • Show the shortest set of validation or repair commands.
    • Distinguish local development problems from distribution problems.

Useful Commands

  • codesign -dvvv --entitlements :- <app-or-binary>
  • spctl -a -vv <app-or-binary>
  • security find-identity -p codesigning -v
  • plutil -p <path-to-entitlements-or-plist>

Guardrails

  • Never invent missing entitlements.
  • Do not conflate notarization with local debug signing.
  • If the real issue is a build setting or provisioning profile, say so directly.

Output Expectations

Provide:

  • what artifact was inspected
  • what signing state it is in
  • the exact failure class
  • the minimum fix or validation sequence

Skills เพิ่มเติมจาก openai

release
openai
สร้าง Symphony release โดยการ bump เวอร์ชันที่ commit ไว้ นำไป merge แท็ก commit ที่รวมแล้ว และตรวจสอบ Burrito release workflow ใช้เมื่อถูกขอให้…
building-ai-agent-on-cloudflare
openai
สร้าง AI agents บน Cloudflare โดยใช้ Agents SDK พร้อมการจัดการสถานะ, WebSockets แบบเรียลไทม์, งานตามกำหนดเวลา, การรวมเครื่องมือ และแชท…
epigraphdb-skill
openai
ส่งคำขอ API EpiGraphDB แบบกระชับสำหรับ ontology, วรรณกรรม, MR, ยีน-ยา และหลักฐานเส้นทางสนับสนุน ใช้เมื่อผู้ใช้ต้องการสรุป EpiGraphDB แบบสั้น
runtime-behavior-probe
openai
วางแผนและดำเนินการตรวจสอบพฤติกรรมขณะรันไทม์ด้วยสคริปต์ตรวจสอบชั่วคราว เมทริกซ์การตรวจสอบ การควบคุมสถานะ และรายงานที่เน้นผลลัพธ์เป็นหลัก ใช้เฉพาะเมื่อ…
deep-security-scan
openai
ใช้เมื่อผู้ใช้ขอการสแกนความปลอดภัยของ Codex แบบเจาะลึก ละเอียดถี่ถ้วน หลายรอบ หรือลดความแปรปรวน ครอบคลุมทั้ง repository หรือเฉพาะเส้นทางที่กำหนด โดยให้รันซ้ำแบบอิสระ…
define-security-policy
openai
กำหนด ทบทวน หรือปรับปรุงแนวทาง SECURITY.md สำหรับ repository หรือ component ใช้เมื่อผู้ใช้ต้องการชี้แจงว่า Codex Security ควรตรวจสอบอะไร สิ่งใดอยู่นอก
validation
openai
ใช้เมื่อ Codex อยู่ในขั้นตอนการตรวจสอบความปลอดภัยแล้ว หรือผู้ใช้ขออย่างชัดเจนให้ระบุว่าข้อค้นพบด้านความปลอดภัยที่อาจเป็นไปได้หนึ่งรายการหรือมากกว่านั้น…
fix-finding
openai
ใช้เมื่อผู้ใช้ขอให้แก้ไขและตรวจสอบความถูกต้องของข้อค้นพบด้านความปลอดภัยที่ได้รับการยืนยันหรือเป็นไปได้อย่างชัดเจน ห้ามใช้เป็นตัวกระตุ้นหลักสำหรับการสร้าง Pull Request, commit, branch, … ทั้งหมด