← Browse

@outthislife/notarize-mac

A

Build and verify a signed, notarized macOS app or DMG using the project's existing notarization automation. Use when the user asks to notarize a Mac build, produce a release DMG, or verify Gatekeeper.

skillclaude

Install

agr install @outthislife/notarize-mac --target claude

Writes 1 file into .claude/skills/, pinned to git-55bc0b17.

  • .claude/skills/notarize-mac/SKILL.md

Document


name: notarize-mac description: >- Build and verify a signed, notarized macOS app or DMG using the project's existing notarization automation. Use when the user asks to notarize a Mac build, produce a release DMG, or verify Gatekeeper.

Notarize macOS Build

Use the project's existing notarization automation. Don't invent a new signing pipeline or expose credentials.

Procedure

  1. Confirm the checkout and branch. Default to a clean, current default branch.
  2. Locate the existing notarization/release script (e.g. a notarize-*-installer.sh or the release script the project already ships):
    • use a path the user supplies first;
    • otherwise search the repo and nearby release/notary checkouts;
    • if none exists, ask for its location instead of recreating it.
  3. Run the script from the environment it expects.
  4. Preserve its signing identity, App Store Connect key handling, artifact naming, and notarization flow.
  5. Verify the resulting artifact with the script's checks or spctl.
  6. Report the artifact path, size, notarization result, and Gatekeeper result.

Never print private key contents, signing credentials, or secret values.

Trustgrade A

  • passBody integrity

    Whether the stored document is plausibly the kind of file the artifact declares, rather than something fetched by mistake.

  • passType matchnot applicable to this artifact type

    Whether the artifact is really the kind of thing its metadata claims it is.

  • passFreshness

    How long since the source repository was last pushed to.

  • passPrompt injection

    Scans the artifact's own text for instructions aimed at your agent rather than at you.

  • passLicense

    Whether the source repository declares an SPDX license permissive enough to redistribute.

How the grade is calculated

Each check contributes 0 points when it passes, 1 when it warns, and 2 when it fails. The total maps to a letter:

  • Aevery check passed
  • Bone warning
  • Ctwo warnings
  • Dprompt injection or body integrity failed, or three warnings
  • Fone of those failed, and something else is wrong

These are automated hygiene checks, not a security audit, and not a dependency or vulnerability scan. A grade of A means nothing was flagged — not that the artifact is safe.

Versions

  • git-55bc0b17d1ef2026-07-31