| name | apple-notes-security-basics |
| description | Apply security best practices for Apple Notes automation scripts.
Trigger: "apple notes security".
|
| allowed-tools | Read, Write, Edit, Bash(osascript:*), Grep |
| version | 1.6.0 |
| license | MIT |
| author | Jeremy Longshore <jeremy@intentsolutions.io> |
| tags | ["saas","macos","apple-notes","automation"] |
| compatibility | Designed for Claude Code |
Apple Notes Security Basics
Overview
Apple Notes security involves three layers: macOS TCC (Transparency, Consent, and Control) which gates which apps can send Apple Events to Notes.app, the macOS sandbox that prevents direct database access, and iCloud encryption that protects notes in transit and at rest. For automation scripts, the primary security concerns are: preventing unauthorized Apple Events access, securing exported note data, avoiding credential leakage in scripts, and understanding the difference between standard and end-to-end encrypted (locked) notes.
Security Checklist
TCC Permission Management
sqlite3 ~/Library/Application\ Support/com.apple.TCC/TCC.db \
"SELECT client, allowed, auth_reason FROM access WHERE service='kTCCServiceAppleEvents';" \
2>/dev/null || echo "Cannot read TCC.db — SIP is active (this is expected)"
tccutil reset AppleEvents
open "x-apple.systempreferences:com.apple.preference.security?Privacy_Automation"
Safe Data Export Pattern
#!/bin/bash
EXPORT_FILE=$(mktemp /tmp/notes-export-XXXXXX.json)
trap 'rm -f "$EXPORT_FILE"' EXIT
umask 077
osascript -l JavaScript -e '
const Notes = Application("Notes");
JSON.stringify(Notes.defaultAccount.notes().map(n => ({
title: n.name(),
body: n.plaintext(),
folder: n.container().name()
})));
' > "$EXPORT_FILE"
echo "Exported to $EXPORT_FILE ($(wc -c < "$EXPORT_FILE") bytes)"
Locked Notes and Encryption
const Notes = Application("Notes");
const allNotes = Notes.defaultAccount.notes();
allNotes.forEach(n => {
try {
const body = n.body();
} catch (e) {
console.log(`Skipping locked note: ${n.name()}`);
}
});
Keychain Integration for Scripts
security add-generic-password -a "notes-automation" -s "notes-export-key" \
-w "your-encryption-key" -T /usr/bin/osascript
KEY=$(security find-generic-password -a "notes-automation" -s "notes-export-key" -w 2>/dev/null)
[ -z "$KEY" ] && echo "ERROR: Keychain credential not found" && exit 1
Error Handling
| Issue | Cause | Solution |
|---|
| TCC prompt never appears | App already denied; macOS won't re-prompt | tccutil reset AppleEvents; retry |
| Cannot read locked notes | End-to-end encrypted; no JXA access | Skip locked notes; document limitation for users |
| Export file readable by other users | Default umask too permissive | Set umask 077 before writing; chmod 600 after |
| Script exposes note content in process list | Note content passed as CLI argument | Pipe content via stdin or temp file instead of -e argument |
| Automation works after upgrade but TCC reset | macOS upgrade clears some TCC entries | Re-approve automation permissions after every OS update |
Resources
Next Steps
For enterprise access control and MDM integration, see apple-notes-enterprise-rbac. For production security validation, see apple-notes-prod-checklist.