Skip to content
Development
Skill

/harden-macos

Review and improve macOS defensive posture. Use for updates, XProtect and Gatekeeper, FileVault, firewall, remote access, accounts, background items, privacy, backups, credentials, and monitoring after a security assessment or incident.

From plugin
socket
7200 skills5 MCP
Install
$ npx -y skills add gaelic-ghost/socket --skill harden-macos --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/harden-macos

Context preview

The summary Claude sees to decide when to auto-load this skill.

Review and improve macOS defensive posture. Use for updates, XProtect and Gatekeeper, FileVault, firewall, remote access, accounts, background items, privacy, backups, credentials, and monitoring after a security assessment or incident.

SKILL.md

harden-macos.SKILL.md
name: harden-macos
description: Review and improve macOS defensive posture. Use for updates, XProtect and Gatekeeper, FileVault, firewall, remote access, accounts, background items, privacy, backups, credentials, and monitoring after a security assessment or incident.

Harden macOS

Overview

Strengthen the actual exposure found on the Mac and verify each change. Preserve built-in protections, user access, recoverability, and organization management requirements.

Read [references/macos-hardening-review.md](references/macos-hardening-review.md) for a risk-ordered review.

Workflow

1. Establish context.

  • Record exact macOS build/hardware, device ownership/management, users, role, exposed services, sensitive data, backups, and the threat being reduced.

2. Apply supported updates.

  • Verify OS, rapid/security data updates, browsers, extensions, apps, and package managers from authoritative channels.

3. Preserve platform protections.

  • Verify Gatekeeper/XProtect automatic protection, SIP, TCC/privacy access, code-signing expectations, and sandbox/container use where applicable.
  • Keep this defensive posture review separate from developer prompt/request implementation; route ordinary app permission design to `macos-privacy-permissions-workflow`.

4. Protect data and recovery.

  • Review FileVault/recovery ownership, screen lock, backup availability and restore testing, account separation, and secure disposal/export practices.

5. Reduce exposed services and persistence.

  • Review sharing, remote login/management, firewall policy, listeners, login/background items, profiles, system/network/browser extensions, and privileged helpers.

6. Improve identity/browser behavior.

  • Review MFA, password manager use, recovery methods, session/token hygiene, download sources, extensions, phishing-resistant habits, and administrator use.

7. Add proportionate visibility.

  • Define which alerts/logs or endpoint tooling are maintained, who reviews them, and how false positives are handled.

8. Verify and document.

  • Re-read changed settings, test access/recovery, record exceptions and owner, and avoid claiming perfect prevention.

Output

Return baseline, prioritized changes, applied/verified settings, deferred items and tradeoffs, recovery check, and residual risk.

Read more
Ships withsocket

Stuff for Agents on macOS Promo audio: Socket Codex Marketplace Promo

Get the whole plugin

Other skills on socket.