apple-developer-toolkit
All-in-one Apple developer skill with three integrated tools shipped as a single unified binary. (1) Documentation search across Apple frameworks, symbols, and 1,267 WWDC sessions from 2014-2025. No credentials needed. (2) App Store Connect CLI with 120+ commands covering builds (find/wait/upload), TestFlight, pre-submission validate, submissions, signing, subscriptions (family-sharable), IAP, analytics, Xcode Cloud, metadata workflows, release pipeline dashboard, insights, win-back offers, promoted purchases, product pages, nominations, accessibility declarations, pre-orders, pricing filters, localizations update, diff, webhooks with local receiver, workflow automation, and more. Requires App Store Connect API key. (3) Multi-platform app builder (iOS/watchOS/tvOS/iPad/macOS/visionOS) that generates complete Swift/SwiftUI apps from natural language with auto-fix, simulator launch, interactive chat mode, and open-in-Xcode. Requires an LLM API key and Xcode. Includes 38 iOS development rules and 12 SwiftUI best practice guides for Liquid Glass, navigation, state management, and modern APIs. All three tools ship as one binary (appledev). USE WHEN: Apple API docs, App Store Connect management, WWDC lookup, or building iOS/watchOS/tvOS/macOS/visionOS apps from scratch. DON'T USE WHEN: non-Apple platforms or general coding.
+ 1 more
Potentially suspicious implementation signals detected: password.
โ๏ธ Quick review
12/12 functionality-v2 checks passed. Pleasantly boring.
abdullah4ai's apple-developer-toolkit was not starting from zero context here โ static analysis already showed shell access, network references, env requirements, 4 blast-radius signals, 1 suspicious signal, which colors how DriftBot reads the runtime results. RatioDaemon version: apple-developer-toolkit cleared functionality-v2 after baseline-v3 without trying anything cute. The most useful observed line was โskill-structure-okโ, which is exactly the kind of unglamorous receipt you want from a clean pass.
baseline safety checks passed8/8 passedclean historyshow baseline lane summary
follow-on functionality checks passed12/12 passedshow follow-on lane summary
Before you install
- You prefer skills that already survived the current runtime lane (functionality-v2).
- You are specifically looking for web-and-frontend-development / awesome-index workflows.
- Expect setup work: this skill references 12 env vars.
- Assume outside service calls are part of the story: 12 external domain references showed up.
- Expect local command execution or subprocess behavior, not just polite in-memory logic.
- Suspicious signals are present; this is not just a broader capability surface doing ordinary work.
- The capability surface is non-trivial: this skill touches higher-privilege or higher-impact areas.
Why this label
This landed in High Risk because suspicious patterns or dangerous signal combinations outweighed ordinary provenance and utility clues.
Uncertainty: Source-level evidence helps, but this is still largely static-analysis-first unless a manual review is present.
Capability surface and suspicious signals
Capability surface
These increase access or impact, but they are not the same thing as deceptive or malicious behavior.
Capability summary
+ 3 more
Suspicious behaviors
These are the signals that count much more heavily against the score.
Evidence
+ 9 more
+ 9 more
+ 2 more
Read this section in two layers: capability surface shows what the skill can touch, while suspicious signals show what looks deceptive or riskier than ordinary integrations.
๐งช Technical runtime details
This is the raw runtime layer: baseline-v3 first, then the follow-on lane when available. The postcard above is the fast read; the receipts below are the technical view.
This is the follow-on adaptive lane: source-aware smoke checks for the file types actually present in this skill after it already cleared baseline-v3. Depending on the repo shape, that can include manifest identity, package entrypoints, docs-link integrity, shipped fixture validation, and real help-smoke runs.
06d23837299b417a81fbfbe31e14dcb08c9bdf6eb104372b82b0ac54c323b075๐งญ skill structurestatus: passedpassedexit 0312 mstap for adaptive receipts
sh -lc test -s /source/SKILL.md && grep -Eq "^#{1,6} " /source/SKILL.md && echo skill-structure-okskill-structure-okโ๐ชช _meta.json shapestatus: passedpassedexit 0315 mstap for adaptive receipts
node -e const fs=require("fs"); const files=process.argv.slice(1); for (const file of files) { const meta=JSON.parse(fs.readFileSync(file, "utf8")); if (!meta || Array.isArray(meta) || typeof meta !== "object") throw new Error(`${file}: _meta.json must be an object`); if (typeof meta.owner !== "string" || !meta.owner) throw new Error(`${file}: owner missing`); if (typeof meta.slug !== "string" || !meta.slug) throw new Error(`${file}: slug missing`); if (!meta.latest || typeof meta.latest !== "object") throw new Error(`${file}: latest missing`); if (typeof meta.latest.version !== "string" || !meta.latest.version) throw new Error(`${file}: latest.version missing`); if (typeof meta.latest.publishedAt !== "number") throw new Error(`${file}: latest.publishedAt missing`); } console.log(`meta-json-shape-ok:${files.length}`); /source/_meta.jsonmeta-json-shape-ok:1โ๐งฌ _meta.json identitystatus: passedpassedexit 0267 mstap for adaptive receipts
node -e const fs=require("fs"); const expectedOwner=process.argv[1]; const expectedSlug=process.argv[2]; const files=process.argv.slice(3); for (const file of files) { const meta=JSON.parse(fs.readFileSync(file, "utf8")); if (meta.owner !== expectedOwner) throw new Error(`${file}: owner mismatch ${meta.owner} !== ${expectedOwner}`); if (meta.slug !== expectedSlug) throw new Error(`${file}: slug mismatch ${meta.slug} !== ${expectedSlug}`); if (meta.history && !Array.isArray(meta.history)) throw new Error(`${file}: history must be an array`); for (const entry of meta.history || []) { if (typeof entry.version !== "string" || !entry.version) throw new Error(`${file}: history.version missing`); if (typeof entry.publishedAt !== "number") throw new Error(`${file}: history.publishedAt missing`); } } console.log(`meta-json-identity-ok:${files.length}`); abdullah4ai apple-developer-toolkit /source/_meta.jsonmeta-json-identity-ok:1โ๐งพ json parsestatus: passedpassedexit 0230 mstap for adaptive receipts
node -e const fs=require("fs"); const files=process.argv.slice(1); for (const file of files) JSON.parse(fs.readFileSync(file, "utf8")); console.log(`json-parse-ok:${files.length}`); /source/_meta.json /source/package.jsonjson-parse-ok:2โ๐ shell syntaxstatus: passedpassedexit 0264 mstap for adaptive receipts
bash -lc for file do bash -n "$file"; done && echo shell-syntax-ok:$# functionality-shell /source/hooks/generate-changelog.sh /source/hooks/git-tag-release.sh /source/hooks/notify-telegram.sh /source/hooks/run-swift-tests.sh /source/scripts/hook-init.sh /source/scripts/hook-runner.sh /source/scripts/setup.shshell-syntax-ok:7โ๐ข node syntaxstatus: passedpassedexit 0256 mstap for adaptive receipts
sh -lc for file do node --check "$file"; done && echo node-syntax-ok:$# functionality-node /source/build-wwdc-index.js /source/cli.jsnode-syntax-ok:2โ๐งช yaml parsestatus: passedpassedexit 0234 mstap for adaptive receipts
eval . /source/templates/hooks-ci.yaml# Apple Developer Toolkit - Hooks Config (CI/CD)
# Automated CI: logging, test running, no interactive notifications
# Config: ~/.appledev/hooks.yaml
version: 1
defaults:
log_dir: "./ci-hook-logs/"
continue_on_error: true
hooks:
build.compile.success:
- name: "run-tests"
run: "~/.appledev/hooks/run-swift-tests.sh"
when: success
build.compile.failure:
- name: "log-failure"
run: "echo '[{{.TIMESTAMP}}] {{.APP_NAME}}: {{.ERROR_COUNT}} errors - {{.ERRORS}}' >> ~/.appledev/hook-logs/build-failures.log"
when: always
build.done:
- name: "log-build"
run: "echo '[{{.TIMESTAMP}}] Build {{.STATUS}} - {{.APP_NAME}} ({{.DURATION_SEC}}s)' >> ~/.appledev/hook-logs/builds.log"โ๐งช yaml parsestatus: passedpassedexit 0227 mstap for adaptive receipts
eval . /source/templates/hooks-indie.yaml# Apple Developer Toolkit - Hooks Config (Indie Dev)
# Solo developer: Telegram notifications + auto TestFlight
# Config: ~/.appledev/hooks.yaml
version: 1
notifiers:
telegram:
enabled: true
hooks:
build.done:
- name: "notify-build-result"
notify: telegram
template: "{{.STATUS}} Build {{.STATUS}} - {{.APP_NAME}} ({{.DURATION_SEC}}s)"
when: always
build.compile.failure:
- name: "log-errors"
run: "echo '[{{.TIMESTAMP}}] {{.APP_NAME}}: {{.ERROR_COUNT}} errors' >> ~/.appledev/hook-logs/build-errors.log"
when: always
store.upload.done:
- name: "notify-upload"โ๐งช yaml parsestatus: passedpassedexit 0226 mstap for adaptive receipts
eval . /source/templates/hooks-team.yaml# Apple Developer Toolkit - Hooks Config (Team)
# Team workflow: Slack + Telegram, git tagging, changelog
# Config: ~/.appledev/hooks.yaml
version: 1
notifiers:
telegram:
enabled: true
slack:
enabled: true
webhook_url_env: "SLACK_WEBHOOK_URL"
hooks:
build.done:
- name: "notify-build"
notify: telegram
template: "{{.STATUS}} Build {{.STATUS}} - {{.APP_NAME}} ({{.DURATION_SEC}}s)"
when: always
build.compile.failure:
- name: "notify-team-failure"
notify: telegramโ๐ฆ package.json shapestatus: passedpassedexit 0240 mstap for adaptive receipts
node -e const fs=require("fs"); const files=process.argv.slice(1); for (const file of files) { const pkg=JSON.parse(fs.readFileSync(file, "utf8")); if (!pkg || Array.isArray(pkg) || typeof pkg !== "object") throw new Error(`${file}: package.json must be an object`); if (pkg.scripts && (Array.isArray(pkg.scripts) || typeof pkg.scripts !== "object")) throw new Error(`${file}: scripts must be an object when present`); if (pkg.dependencies && (Array.isArray(pkg.dependencies) || typeof pkg.dependencies !== "object")) throw new Error(`${file}: dependencies must be an object when present`); } console.log(`package-json-shape-ok:${files.length}`); /source/package.jsonpackage-json-shape-ok:1โ๐ช package entrypointsstatus: passedpassedexit 0240 mstap for adaptive receipts
node -e const fs=require("fs"); const path=require("path"); const exts=["",".js",".mjs",".cjs",".json","/index.js","/index.mjs","/index.cjs"]; const existsTarget=(base,target)=>{ if (typeof target !== "string" || !target || /^(node:|https?:|@)/.test(target)) return true; const resolved=path.resolve(base,target); return exts.some((suffix)=>fs.existsSync(resolved + suffix)); }; const files=process.argv.slice(1); for (const file of files) { const pkg=JSON.parse(fs.readFileSync(file, "utf8")); const base=path.dirname(file); if (typeof pkg.main === "string" && !existsTarget(base,pkg.main)) throw new Error(`${file}: missing main target ${pkg.main}`); if (typeof pkg.bin === "string" && !existsTarget(base,pkg.bin)) throw new Error(`${file}: missing bin target ${pkg.bin}`); if (pkg.bin && typeof pkg.bin === "object" && !Array.isArray(pkg.bin)) { for (const [name,target] of Object.entries(pkg.bin)) { if (!existsTarget(base,target)) throw new Error(`${file}: missing bin target for ${name}: ${target}`); } } } console.log(`package-json-entrypoints-ok:${files.length}`); /source/package.jsonpackage-json-entrypoints-ok:1โ๐ docs link integritystatus: passedpassedexit 0308 mstap for adaptive receipts
python3 -c import pathlib, re, sys
root=pathlib.Path("/source").resolve()
pattern=re.compile(r"[[^]]+](([^)]+))")
missing=[]
checked=0
for file in [pathlib.Path(p) for p in sys.argv[1:]]:
try:
text=file.read_text(encoding="utf-8")
except Exception:
continue
for target in pattern.findall(text):
target=target.strip().strip("<>")
if not target or target.startswith(("http://","https://","mailto:","#")):
continue
target=target.split("#",1)[0].strip()
if not target:
continue
checked += 1
resolved=(file.parent / target).resolve()
try:
resolved.relative_to(root)
except ValueError:
missing.append(f"{file}: outside-source link -> {target}")
continue
if not resolved.exists():
missing.append(f"{file}: missing -> {target}")
if missing:
raise SystemExit("\n".join(missing[:20]))
print(f"docs-local-links-ok:{checked}") /source/README.md /source/references/app-store-connect.md /source/references/hooks-reference.md /source/references/ios-app-builder-prompts.md /source/references/ios-rules/accessibility.md /source/references/ios-rules/app_clips.md /source/references/ios-rules/app_review.md /source/references/ios-rules/apple_translation.md /source/references/ios-rules/biometrics.md /source/references/ios-rules/camera.md /source/references/ios-rules/charts.md /source/references/ios-rules/color_contrast.md /source/references/ios-rules/components.md /source/references/ios-rules/dark_mode.md /source/references/ios-rules/design-system.md /source/references/ios-rules/feedback_states.md /source/references/ios-rules/file-structure.md /source/references/ios-rules/forbidden-patterns.md /source/references/ios-rules/foundation_models.md /source/references/ios-rules/gestures.md /source/references/ios-rules/haptics.md /source/references/ios-rules/healthkit.md /source/references/ios-rules/live_activities.md /source/references/ios-rules/localization.mdโโ06d23837299b417a81fbfbe31e14dcb08c9bdf6eb104372b82b0ac54c323b075๐ฆ Source mountstatus: passedpassedexit 0266 mstap for the raw receipts
sh -lc find /source -maxdepth 2 -type f | sort | sed -n "1,12p" > /workspace/source-files.txt && wc -l /workspace/source-files.txt && cat /workspace/source-files.txtbusybox@sha256:b9598f8c98e24d0ad42c1742c32516772c3aa2151011ebaf639089bd18c605b88c9f60350fa8dc92efbab7b7d4baef54eef33072a40525390d49534c59dbed0de3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855Observed stdout:
12 /workspace/source-files.txt /source/README.md /source/SKILL.md /source/_meta.json /source/build-wwdc-index.js /source/cli.js /source/hooks/generate-changelog.sh /source/hooks/git-tag-release.sh /source/hooks/notify-telegram.sh /source/hooks/run-swift-tests.sh /source/package.json /source/references/app-store-connect.md /source/references/hooks-reference.md
Observed stderr:
(empty)
Workspace artifacts:
- source-files.txt (331 B)
๐ Source write guardstatus: passedpassedexit 0223 mstap for the raw receipts
sh -lc touch /source/driftbot-write-test >/tmp/source-write.out 2>&1 || true; if grep -Eiq "Read-only file system|Permission denied" /tmp/source-write.out || [ ! -e /source/driftbot-write-test ]; then echo source-readonly; fibusybox@sha256:b9598f8c98e24d0ad42c1742c32516772c3aa2151011ebaf639089bd18c605b8a65af92097dc754e9cac4a455c5378d78b05e7927705ae45e1d20a24c4c1fd3ce3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855Observed stdout:
source-readonly
Observed stderr:
(empty)
Workspace artifacts:
No workspace artifacts produced.
๐ Workspace writestatus: passedpassedexit 0224 mstap for the raw receipts
sh -lc echo workspace-ok > /workspace/write-check.txt && grep -q "workspace-ok" /workspace/write-check.txt && echo workspace-write-okbusybox@sha256:b9598f8c98e24d0ad42c1742c32516772c3aa2151011ebaf639089bd18c605b881487f7df7b83c1d3fae9c36fb1009328fa34feca0f5c1581674de4cba29e6f5e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855Observed stdout:
workspace-write-ok
Observed stderr:
(empty)
Workspace artifacts:
- write-check.txt (13 B)
๐ Hostname network denialstatus: passedpassedexit 0227 mstap for the raw receipts
sh -lc wget -T 3 -qO- http://example.com >/tmp/http-host.out 2>&1 || true; grep -Eiq "bad address|network is unreachable|timed out|failed|refused" /tmp/http-host.out && echo network-host-blockedbusybox@sha256:b9598f8c98e24d0ad42c1742c32516772c3aa2151011ebaf639089bd18c605b8aa4c95f392f2c19669ae67769237c23b54efb5f5e26a8ac8f11162ef28e7f141e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855Observed stdout:
network-host-blocked
Observed stderr:
(empty)
Workspace artifacts:
No workspace artifacts produced.
๐งฑ Raw-IP network denialstatus: passedpassedexit 0239 mstap for the raw receipts
sh -lc wget -T 3 -qO- http://1.1.1.1 >/tmp/http-ip.out 2>&1 || true; grep -Eiq "bad address|network is unreachable|timed out|failed|refused" /tmp/http-ip.out && echo network-ip-blockedbusybox@sha256:b9598f8c98e24d0ad42c1742c32516772c3aa2151011ebaf639089bd18c605b8ee48345f6e97282a8b1f42753df3c9b37886403c60b09a044657b95126bae8b1e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855Observed stdout:
network-ip-blocked
Observed stderr:
(empty)
Workspace artifacts:
No workspace artifacts produced.
๐งช Fake-env handlingstatus: passedpassedexit 0228 mstap for the raw receipts
sh -lc env | grep -E "OPENAI_API_KEY|SLACK_BOT_TOKEN|GITHUB_TOKEN" | sed "s/=.*$/=REDACTED/"busybox@sha256:b9598f8c98e24d0ad42c1742c32516772c3aa2151011ebaf639089bd18c605b8d714e2d3c2043f53d26d2deebac9b26a17f96f8d20158469b586bb598bc80c57e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855Observed stdout:
GITHUB_TOKEN=REDACTED SLACK_BOT_TOKEN=REDACTED OPENAI_API_KEY=REDACTED
Observed stderr:
(empty)
Workspace artifacts:
No workspace artifacts produced.
๐๏ธ Secret-path isolationstatus: passedpassedexit 0224 mstap for the raw receipts
sh -lc test ! -e /root/.ssh && test ! -e /home/claw1/.ssh && test ! -e /workspace/.ssh && echo no-host-secretsbusybox@sha256:b9598f8c98e24d0ad42c1742c32516772c3aa2151011ebaf639089bd18c605b8e95cf953e01cafd431be70f0f5539c4c0ae8961ef5cff96d968a29509597c797e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855Observed stdout:
no-host-secrets
Observed stderr:
(empty)
Workspace artifacts:
No workspace artifacts produced.
๐ณ Docker socket denialstatus: passedpassedexit 0224 mstap for the raw receipts
sh -lc test ! -S /var/run/docker.sock && echo no-docker-socketbusybox@sha256:b9598f8c98e24d0ad42c1742c32516772c3aa2151011ebaf639089bd18c605b8702d41c3742c72aff24f584ad0138f2df38b424090d03d3b3e85e3212f0df2efe3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855Observed stdout:
no-docker-socket
Observed stderr:
(empty)
Workspace artifacts:
No workspace artifacts produced.
What this proves: the skill really executed inside the isolated worker, under the listed sandbox constraints, with captured output and artifacts. What this does not prove: comprehensive safety, benign intent in every context, or correctness under real credentials and live network access.
Publisher and provenance
Listed in the VoltAgent awesome-openclaw-skills catalog under Web And Frontend Development and lightly source-scanned from openclaw/skills. This is stronger evidence than catalog metadata alone, but still not a full runtime audit.
Source type: awesome-index
Source path: https://github.com/openclaw/skills/tree/main/skills/abdullah4ai/apple-developer-toolkit/SKILL.md
Source URL: https://github.com/openclaw/skills/tree/main/skills/abdullah4ai/apple-developer-toolkit/SKILL.md
Discovery category: Web And Frontend Development
Manual review
No human review yet. The scorecard is currently static-analysis-first.
Community signals
Community signals
These are community attention markers, not crowd-sourced truth. Click what feels especially worth flagging or reviewing.
Related skills
kefir-batch-manager
Comprehensive kรฉfir batch management system with cycle tracking, intelligent reminders, grain health monitoring, and recipe management. Use when managing kรฉfir fermentation cycles, tracking grain health, calculating ratios, scheduling reminders, or maintaining fermentation records.
echo-agent
EchoAgent is a minimal OpenClaw-compatible skill.
japanese-tutor
Interactive Japanese learning assistant. Supports vocabulary, grammar, quizzes, roleplay, PDF/DOCX material parsing for study/homework help, and OCR translation.