Skip to content
Development
Skill

/use-objective-see-tools

Use installed Objective-See macOS security tools as evidence adapters. Use for KnockKnock, BlockBlock, LuLu, ProcessMonitor, FileMonitor, WhatsYourSign, TaskExplorer, or related tools with explicit permissions, limits, and ownership.

From plugin
socket
7200 skills5 MCP
Install
$ npx -y skills add gaelic-ghost/socket --skill use-objective-see-tools --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/use-objective-see-tools

Context preview

The summary Claude sees to decide when to auto-load this skill.

Use installed Objective-See macOS security tools as evidence adapters. Use for KnockKnock, BlockBlock, LuLu, ProcessMonitor, FileMonitor, WhatsYourSign, TaskExplorer, or related tools with explicit permissions, limits, and ownership.

SKILL.md

use-objective-see-tools.SKILL.md
name: use-objective-see-tools
description: Use installed Objective-See macOS security tools as evidence adapters. Use for KnockKnock, BlockBlock, LuLu, ProcessMonitor, FileMonitor, WhatsYourSign, TaskExplorer, or related tools with explicit permissions, limits, and ownership.

Use Objective-See Tools

Overview

Select the Objective-See tool that observes the needed surface, record its current capabilities, and return evidence to the owning macOS workflow. Do not treat one tool's label or UI color as a threat verdict.

Read [references/objective-see-routing.md](references/objective-see-routing.md) and recheck the official tool page before use.

Workflow

1. Name the unresolved observation: persistence, process, file, network, signing, or process inventory. 2. Discover local capability.

  • Verify official source, installed app/path, version, supported macOS build, permissions/system extensions, running state, and export format.
  • Do not install, approve extensions, or grant privacy access without an explicit operator decision.

3. Select one tool and bounded action. 4. Preserve context.

  • Record scan time, filters, exclusions, baseline, UI/CLI actions, alerts, raw/exported output, and tool errors.

5. Correlate independently.

  • Verify signer/path/hash, process ancestry, persistence registration, socket, or file change with native evidence where practical.

6. Route conclusions.

  • Send evidence to persistence, runtime, threat assessment, or containment workflows.

Guardrails

  • Do not enable blocking rules or terminate/delete items during evidence collection unless containment is separately approved.
  • Do not claim historical coverage when the tool was installed after the event.
  • Do not assume every Objective-See tool exposes a stable CLI or accessible GUI automation surface.

Output

Return tool/version/capability, permissions, action, observations/export, independent correlation, limitations, and owning workflow.

Read more
Ships withsocket

Stuff for Agents on macOS Promo audio: Socket Codex Marketplace Promo

Get the whole plugin

Other skills on socket.