All skills
simota avatar

/hearth

@16a3f28
by shingo imotasimota/agent-skills85 stars
15

Generating and auditing personal dev environment configs (zsh/tmux/neovim/ghostty) and automating the macOS desktop via AppleScript/JXA (Finder, Mail, Safari). Use for dotfiles or Apple Events.

Use this Skill: https://skilld.dev/gh/simota/agent-skills/hearth

This session only. Nothing lands on disk.

referenceosascript-integration.md

≈828 tokens on demand. Your agent reads this file only when SKILL.md points to it.

osascript & Cross-Language Integration

osascript runs AppleScript and JXA from the shell, scripts, and other languages. Prefer files/heredocs over fragile inline one-liners.

Invocation forms

# Inline AppleScript
osascript -e 'tell application "Safari" to get URL of front document'

# Multi-line via -e (each line a separate -e)
osascript -e 'tell application "Finder"' -e 'get count of items of desktop' -e 'end tell'

# Script file
osascript automation.applescript

# JXA
osascript -l JavaScript -e 'Application("Safari").windows[0].currentTab.url()'

# JXA REPL (interactive)
osascript -il JavaScript

Shebang scripts

#!/usr/bin/osascript
-- chmod +x notify.applescript  →  ./notify.applescript
display notification "Build done" with title "CI"
#!/usr/bin/osascript -l JavaScript
const app = Application.currentApplication();
app.includeStandardAdditions = true;
app.displayNotification("Build done", { withTitle: "CI" });

Heredoc (reproducible multi-line from shell)

osascript <<'APPLESCRIPT'
tell application "Music"
    if player state is playing then pause
end tell
APPLESCRIPT

Use a quoted heredoc delimiter ('APPLESCRIPT') to stop the shell from expanding $ and backticks inside the script.

Passing arguments & capturing output

# Args arrive as `on run argv`
osascript greet.applescript "World"
on run argv
    return "Hello, " & (item 1 of argv)
end run
  • stdout: the script's return value is printed to stdout.
  • exit code: a script error yields a non-zero exit; trap in shell with if ! osascript … ; then.
  • stderr: errors print to stderr — capture with 2>.

From Python

import subprocess

def run_osascript(script: str) -> str:
    # Never interpolate untrusted input into `script` — for dynamic values use a
    # script file with `on run argv` and pass them as separate args (below).
    p = subprocess.run(["osascript", "-e", script],
                       capture_output=True, text=True)
    if p.returncode != 0:
        # stderr carries the full error string, e.g.
        # "execution error: Not authorized to send Apple events to … (-1743)"
        raise RuntimeError(p.stderr.strip())
    return p.stdout.strip()

url = run_osascript('tell application "Safari" to get URL of front document')

The PyPI osascript package wraps this (run() returns code/stdout/stderr) but is lightly maintained — subprocess is the dependency-free path.

From Node.js

const { execFile } = require("node:child_process");

function osa(script) {
  return new Promise((resolve, reject) => {
    execFile("osascript", ["-e", script], (err, stdout, stderr) =>
      err ? reject(new Error(stderr || err.message)) : resolve(stdout.trim()));
  });
}
await osa('tell application "Music" to playpause');

node-osascript exists but child_process.execFile (no shell, avoids injection) is the safer default. Never build osascript strings from untrusted input via a shell — pass as a discrete arg.

Quoting cheatsheet

  • Shell single-quote the whole -e payload; use AppleScript's own " inside.
  • For dynamic values, pass via argv / on run, not string concatenation, to avoid quoting bugs and injection.

Source: SKILL.md on GitHub

2 warnings5mo5 checks · Risk SAFE
  • Gen Agent Trust Hub5mo

    Hearth is a personal environment management skill designed to configure and optimize developer dotfiles for shells, terminals, and editors. It emphasizes security best practices, including secret detection with Gitleaks and adherence to XDG Base Directory standards. The skill utilizes industry-standard tools and fetches dependencies from trusted or well-known open-source repositories.

  • Socket5mo

    No alerts

  • Snyk5mo

    Risk: MEDIUM · 2 issues

  • Runlayer6mo

    4/10 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 16a3f28. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated last month

README badge

README badge for simota/agent-skills/hearth