with one click
mac-security-audit
Run a comprehensive READ-ONLY macOS security audit and triage the findings. Checks open/listening ports and external exposure, firewall + stealth, SSH and remote access (Screen Sharing, ARD), VPN/tunnels (Tailscale, WireGuard, reverse SSH), persistence (LaunchAgents/Daemons, cron, login hooks, shell rc, BTM / background items, system & network extensions, kext, authorization plugins), trusted root certificates (MITM vector), running process locations & code signatures, plaintext secrets (.env/.netrc/.aws/shell history — paths only), SSH key hygiene + authorized_keys, users/admins/autologin, login history, recent files, browser extensions, TCC privacy permissions (Accessibility, Input Monitoring, Screen Recording, Full Disk Access), and leaked API tokens in AI agent session logs (Claude Code / Codex / Cursor / Windsurf), OS update status, code signatures of installed apps, app provenance (quarantine), backups (Time Machine) and screen-lock settings, browser saved-password counts, IDE extensions (VS Code/Cursor
Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.