Back to skill

Security audit

macOS CLT Offline Install

Security checks for vulnerabilities and agentic risk

Overview

This skill provides a disclosed, purpose-aligned workflow for manually installing macOS Command Line Tools from Apple update catalogs.

Before running the generated sudo script, confirm the packages came from Apple's swcdn/swscan update URLs and that pkgutil reports valid Apple signatures. The skill is not risk-free because it changes system developer-tool configuration, but that access is expected for installing CLT.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.