@outthislife/notarize-mac
ABuild and verify a signed, notarized macOS app or DMG using the project's existing notarization automation. Use when the user asks to notarize a Mac build, produce a release DMG, or verify Gatekeeper.
Install
agr install @outthislife/notarize-mac --target claudeWrites 1 file into .claude/skills/, pinned to git-55bc0b17.
- .claude/skills/notarize-mac/SKILL.md
Document
name: notarize-mac description: >- Build and verify a signed, notarized macOS app or DMG using the project's existing notarization automation. Use when the user asks to notarize a Mac build, produce a release DMG, or verify Gatekeeper.
Notarize macOS Build
Use the project's existing notarization automation. Don't invent a new signing pipeline or expose credentials.
Procedure
- Confirm the checkout and branch. Default to a clean, current default branch.
- Locate the existing notarization/release script (e.g. a
notarize-*-installer.shor the release script the project already ships):- use a path the user supplies first;
- otherwise search the repo and nearby release/notary checkouts;
- if none exists, ask for its location instead of recreating it.
- Run the script from the environment it expects.
- Preserve its signing identity, App Store Connect key handling, artifact naming, and notarization flow.
- Verify the resulting artifact with the script's checks or
spctl. - Report the artifact path, size, notarization result, and Gatekeeper result.
Never print private key contents, signing credentials, or secret values.
Trustgrade A
- passBody integrity
Whether the stored document is plausibly the kind of file the artifact declares, rather than something fetched by mistake.
- passType matchnot applicable to this artifact type
Whether the artifact is really the kind of thing its metadata claims it is.
- passFreshness
How long since the source repository was last pushed to.
- passPrompt injection
Scans the artifact's own text for instructions aimed at your agent rather than at you.
- passLicense
Whether the source repository declares an SPDX license permissive enough to redistribute.
How the grade is calculated
Each check contributes 0 points when it passes, 1 when it warns, and 2 when it fails. The total maps to a letter:
- Aevery check passed
- Bone warning
- Ctwo warnings
- Dprompt injection or body integrity failed, or three warnings
- Fone of those failed, and something else is wrong
These are automated hygiene checks, not a security audit, and not a dependency or vulnerability scan. A grade of A means nothing was flagged — not that the artifact is safe.
Versions
git-55bc0b17d1ef2026-07-31