All skills
simota avatar

/hearth

@16a3f28
by shingo imotasimota/agent-skills85 stars
15

Generating and auditing personal dev environment configs (zsh/tmux/neovim/ghostty) and automating the macOS desktop via AppleScript/JXA (Finder, Mail, Safari). Use for dotfiles or Apple Events.

Use this Skill: https://skilld.dev/gh/simota/agent-skills/hearth

This session only. Nothing lands on disk.

referencepermissions-tcc.md

≈815 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Permissions & TCC (Transparency, Consent, and Control)

Since macOS Mojave (2018), Apple Events between apps are gated by TCC. Designing around consent is half the job of a reliable automation.

The consent model

  • Permission is per (source app, target app) pair. The first time process A sends an Apple Event to app B, the user gets one prompt: "A wants to control B."
  • Denial returns AppleScript error -1743 (errAEEventNotPermitted).
  • Granted/denied state lives in System Settings → Privacy & Security → Automation (the user can revoke later).
  • StandardAdditions verbs (display dialog, do shell script, display notification, clipboard) run in-process and do not prompt — unless they appear inside a tell application "Other" block, which scopes them to that app.

Permission surfaces

Capability Where to grant Triggered by
Controlling another app Privacy & Security → Automation tell application "X" to a different app
UI scripting (clicks/keystrokes) Privacy & Security → Accessibility System Events Processes Suite
Reading protected files (Mail, Messages, Desktop, Documents) Privacy & Security → Full Disk Access file reads in protected locations

Handling -1743 gracefully

try
    tell application "Notes" to set n to count of notes
on error errMsg number errNum
    if errNum is -1743 then
        return "Grant Automation permission: System Settings > Privacy & Security > Automation > [this app] > enable Notes."
    end if
    error errMsg number errNum
end try

Design rules

  1. Name the consent pairs up front. List every (source → target) prompt the user will see before they run the script — surprise prompts read as malware.
  2. Minimize target apps. Each extra tell to a new app is another prompt and another revocable permission. Drop apps the task doesn't need.
  3. Keep StandardAdditions in-process. Put display dialog / do shell script at the top level, not inside another app's tell, to avoid needless prompts.
  4. Never instruct disabling TCC/SIP. "Just turn off the protection" is not a fix — design within consent. Resetting a stuck grant is tccutil reset AppleEvents (the user runs it knowingly), not disabling enforcement. The service name is case-sensitive; if that string is rejected on your macOS version, try tccutil reset Automation.
  5. Unattended runs need pre-granted consent. A launchd/cron/login-item automation cannot answer a prompt — the permission must already be granted (or, in managed fleets, pre-approved via MDM PPPC profiles, which is out of Hearth's scope to deploy).

Security note

  • TCC and the Apple Events consent path have a history of bypass CVEs (e.g., CVE-2025-43530 was reported as an Apple Events-related TCC bypass — verify the exact mechanism and fixed version against Apple Security Releases before citing specifics). Keep macOS patched; never design an automation that depends on a TCC bypass.
  • Don't author automations whose intent is to evade consent, surveil, or access data without authorization. See _common/SECURITY.md.

Source: SKILL.md on GitHub

2 warnings5mo5 checks · Risk SAFE
  • Gen Agent Trust Hub5mo

    Hearth is a personal environment management skill designed to configure and optimize developer dotfiles for shells, terminals, and editors. It emphasizes security best practices, including secret detection with Gitleaks and adherence to XDG Base Directory standards. The skill utilizes industry-standard tools and fetches dependencies from trusted or well-known open-source repositories.

  • Socket5mo

    No alerts

  • Snyk5mo

    Risk: MEDIUM · 2 issues

  • Runlayer6mo

    4/10 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 16a3f28. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated last month

README badge

README badge for simota/agent-skills/hearth