All skills
simota avatar

/hearth

@16a3f28
by shingo imotasimota/agent-skills85 stars
15

Generating and auditing personal dev environment configs (zsh/tmux/neovim/ghostty) and automating the macOS desktop via AppleScript/JXA (Finder, Mail, Safari). Use for dotfiles or Apple Events.

Use this Skill: https://skilld.dev/gh/simota/agent-skills/hearth

This session only. Nothing lands on disk.

referencesafety-and-testing.md

≈733 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Safety, Dry-Run & Testing

Every Hearth automate script must be safe to re-run and safe to test. Destructive actions are gated; read paths are validated before delivery.

Destructive operation catalog

Treat these as destructive — gate behind a dry-run flag or explicit confirmation:

  • Mail/Messages: send
  • Finder/filesystem: delete, move … to trash, empty trash, overwriting files
  • Notes/Calendar/Reminders/Contacts: delete, bulk set/overwrite
  • Music/Photos: delete, library mutation
  • do shell script with rm, mv, >, sudo, network calls
  • System Events: keystroke/click that commits an irreversible UI action

Dry-run pattern

property DRY_RUN : true  -- default safe; flipped by argv below

on run argv
    if argv contains "--apply" then set DRY_RUN to false
    -- … call your handlers …
end run

on archiveMessage(msg)
    if DRY_RUN then
        log "[DRY-RUN] would archive: " & (subject of msg)
    else
        tell application "Mail" to set mailbox of msg to mailbox "Archive"
    end if
end archiveMessage

For shell callers, the flag must be parsed in on run argv (osascript has no built-in --dry-run flag — every token after the script name is raw argv):

osascript clean.applescript            # DRY_RUN stays true; prints intended actions
osascript clean.applescript --apply    # parsed by `on run argv` → performs them

Idempotency

Re-running must not duplicate or corrupt. Check-before-create:

tell application "Notes" to tell account "iCloud"
    if not (exists note "Daily Log") then
        make new note with properties {name:"Daily Log"}
    end if
end tell
  • Creating events/notes/files: check existence (by name/id) first, or use a stable identifier.
  • Toggles (playpause): prefer explicit state checks (if player state is playing) over blind toggles when the outcome must be deterministic.

Validating before delivery

  1. Read-only first. Run the query/read parts with osascript and confirm the values are real.
  2. Stub destructive calls. Keep DRY_RUN true; confirm the log lines describe the right actions on the right targets.
  3. Permission smoke test. Trigger each tell once to confirm consent is grantable and -1743 is handled.
  4. Idempotency check. Run twice; assert no duplicates / no drift.
  5. Exit codes. For shell/CI use, confirm errors yield non-zero exit and clear stderr.

Delivery checklist (attach to every automation)

  • Target apps + scriptability (dictionary vs UI scripting) listed
  • Required TCC permissions named with grant path
  • Destructive actions identified and gated
  • Dry-run validated; idempotency confirmed
  • Exact run command provided
  • No secrets in plaintext (use Keychain via security find-generic-password)
  • macOS-version caveats noted if any (e.g., Tahoe Music/TV/Finder regressions)

Source: SKILL.md on GitHub

2 warnings5mo5 checks · Risk SAFE
  • Gen Agent Trust Hub5mo

    Hearth is a personal environment management skill designed to configure and optimize developer dotfiles for shells, terminals, and editors. It emphasizes security best practices, including secret detection with Gitleaks and adherence to XDG Base Directory standards. The skill utilizes industry-standard tools and fetches dependencies from trusted or well-known open-source repositories.

  • Socket5mo

    No alerts

  • Snyk5mo

    Risk: MEDIUM · 2 issues

  • Runlayer6mo

    4/10 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 16a3f28. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated last month

README badge

README badge for simota/agent-skills/hearth