Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions .claude-plugin/marketplace.json
Original file line number Diff line number Diff line change
Expand Up @@ -9,11 +9,11 @@
{ "name": "agent-portability-skills", "source": "./plugins/agent-portability-skills", "description": "Cross-host agent-skill and plugin portability workflows.", "category": "developer-tools", "tags": ["skills", "portability"], "strict": false },
{ "name": "android-dev-skills", "source": "./plugins/android-dev-skills", "description": "Android, Kotlin, Java, Gradle, testing, and release workflows.", "category": "developer-tools", "tags": ["android", "skills"], "strict": false },
{ "name": "apple-creator-studio-skills", "source": "./plugins/apple-creator-studio-skills", "description": "Apple Creator Studio workflows for production and delivery.", "category": "productivity", "tags": ["apple", "creative"], "strict": false },
{ "name": "apple-dev-skills", "source": "./plugins/apple-dev-skills", "description": "Apple, SwiftPM extension, Swift, Xcode, and platform-development workflows.", "category": "developer-tools", "tags": ["apple", "swift", "swiftpm", "xcode"], "mcpServers": "./.mcp.json", "strict": false },
{ "name": "apple-dev-skills", "source": "./plugins/apple-dev-skills", "description": "Apple, SwiftPM, Xcode, and macOS or Linux virtualization workflows.", "category": "developer-tools", "tags": ["apple", "swift", "swiftpm", "xcode", "virtualization"], "mcpServers": "./.mcp.json", "strict": false },
{ "name": "cardhop-app", "source": "./plugins/cardhop-app", "description": "Cardhop contact workflows with a Claude Code local MCP server.", "category": "productivity", "tags": ["contacts", "macos", "local-mcp"], "mcpServers": "./claude.mcp.json", "strict": false },
{ "name": "cloud-deployment-skills", "source": "./plugins/cloud-deployment-skills", "description": "Cloud deployment routing and provider integration workflows.", "category": "developer-tools", "tags": ["cloud", "deployment"], "strict": false },
{ "name": "cloud-inference-skills", "source": "./plugins/cloud-inference-skills", "description": "Cloud AI inference, training, conversion, and GPU workflows.", "category": "developer-tools", "tags": ["ai", "cloud", "mcp"], "mcpServers": "./.mcp.json", "strict": false },
{ "name": "cybersecurity-skills", "source": "./plugins/cybersecurity-skills", "description": "Security analysis, incident response, and defensive workflow skills.", "category": "developer-tools", "tags": ["security", "skills"], "strict": false },
{ "name": "cybersecurity-skills", "source": "./plugins/cybersecurity-skills", "description": "Security analysis, isolated lab, incident response, and defensive workflows.", "category": "developer-tools", "tags": ["security", "analysis-lab", "skills"], "strict": false },
{ "name": "dotnet-skills", "source": "./plugins/dotnet-skills", "description": ".NET, F#, C#, ASP.NET Core, and tooling workflows.", "category": "developer-tools", "tags": ["dotnet", "csharp", "fsharp"], "strict": false },
{ "name": "game-dev-skills", "source": "./plugins/game-dev-skills", "description": "Apple game-development workflows for Metal, SpriteKit, SceneKit, and gameplay systems.", "category": "developer-tools", "tags": ["games", "apple", "metal"], "strict": false },
{ "name": "messaging-collaboration-skills", "source": "./plugins/messaging-collaboration-skills", "description": "Messaging, collaboration, communication, and meeting workflows.", "category": "productivity", "tags": ["messaging", "collaboration"], "strict": false },
Expand All @@ -24,7 +24,7 @@
{ "name": "reverse-engineering-skills", "source": "./plugins/reverse-engineering-skills", "description": "Artifact triage, binary analysis, and reproducible evidence workflows.", "category": "developer-tools", "tags": ["reverse-engineering", "security"], "strict": false },
{ "name": "rust-skills", "source": "./plugins/rust-skills", "description": "Rust, Cargo, crate, test, CI, and package workflows.", "category": "developer-tools", "tags": ["rust", "cargo"], "strict": false },
{ "name": "server-side-jvm", "source": "./plugins/server-side-jvm", "description": "Java, Scala, JVM service, build, and testing workflows.", "category": "developer-tools", "tags": ["java", "scala", "jvm"], "strict": false },
{ "name": "server-side-swift", "source": "./plugins/server-side-swift", "description": "Vapor, Hummingbird, SwiftNIO, and server-side Swift workflows.", "category": "developer-tools", "tags": ["swift", "server"], "strict": false },
{ "name": "server-side-swift", "source": "./plugins/server-side-swift", "description": "Vapor, Hummingbird, SwiftNIO, Docker, and Apple container workflows.", "category": "developer-tools", "tags": ["swift", "server", "containers"], "strict": false },
{ "name": "swift-lang", "source": "./plugins/swift-lang", "description": "Shared Swift language, syntax, compiler, semantic indexing, LSP, formatting, and modernization workflows.", "category": "developer-tools", "tags": ["swift", "language", "tooling"], "strict": false },
{ "name": "swiftasb-skills", "source": "./plugins/swiftasb-skills", "description": "SwiftASB integration and application-development workflows.", "category": "developer-tools", "tags": ["swift", "swiftasb"], "strict": false },
{ "name": "things-app", "source": "./plugins/things-app", "description": "Things planning and reminder workflows with a Claude Code local MCP server.", "category": "productivity", "tags": ["things", "macos", "local-mcp"], "mcpServers": "./claude.mcp.json", "strict": false },
Expand Down
6 changes: 3 additions & 3 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -148,11 +148,11 @@ Current Socket catalog shape:
- `agent-portability-skills`: maintainer skills plus a source-bundled guidance-sync custom-agent definition for Socket-owned agent skill portability, Codex plugin surfaces, and host adapter guidance
- `android-dev-skills`: Android, Kotlin, Java, Gradle, Android Gradle Plugin, Compose/XML UI, testing, lint, emulator-aware validation handoff, and release-readiness workflow guidance
- `apple-creator-studio-skills`: source-preserving Final Cut Pro editing, Motion template, Compressor delivery, Logic Pro production, MainStage concert, and GarageBand project workflows with local Help Viewer discovery, explicit Computer Use safeguards, and artifact or rehearsal verification
- `apple-dev-skills`: Apple, Swift, SwiftPM package plugins/macros/traits, Core Image and Image I/O, Vision and Core ML recognition, AVFoundation camera and depth capture, ARKit spatial sensing, VideoToolbox and Core Video codecs, PhotosUI and PhotoKit, AVFAudio, Core Media, Core Audio, SwiftUI, AppKit, Xcode, Safari, OpenAPI, and DocC workflows, plus the source-bundled `swift-steward` custom-agent definition with its own roadmap
- `apple-dev-skills`: Apple, Swift, SwiftPM, macOS-hosted boundary selection, custom Virtualization framework hosts, persistent Linux development guests, clean macOS development guests, imaging, Vision/Core ML, camera, spatial sensing, media/audio, SwiftUI, AppKit, Xcode, Safari, OpenAPI, and DocC workflows, plus the source-bundled `swift-steward` custom-agent definition with its own roadmap
- `cardhop-app`: mixed skill plus bundled MCP server for Cardhop.app contact workflows
- `cloud-deployment-skills`: cloud provider deployment routing, official provider plugin selection, credential and mutation boundary checks, and AWS handoff to the official AWS Agent Toolkit rather than duplicated AWS MCP, CLI, or SAM setup
- `cloud-inference-skills`: cloud AI inference, training, model conversion, and GPU infrastructure routing for Runpod, Hugging Face, AWS, Vast.ai, CoreWeave, and similar providers, with bundled Runpod MCP server configuration, upstream Runpod skill mirrors, and first-party Hugging Face/AWS handoffs
- `cybersecurity-skills`: suspicious-content triage, evidence preservation, malware analysis, isolation, agentic security-tool controls, macOS investigation and defense, vulnerability validation, authorized web/API and network testing, incident response, threat hunting, detection content, and clear non-specialist advice
- `cybersecurity-skills`: suspicious-content triage, evidence preservation, isolation selection, disposable Linux and macOS analysis-lab preparation, malware analysis, agentic security-tool controls, macOS investigation and defense, vulnerability validation, authorized testing, incident response, threat hunting, detection content, and clear non-specialist advice
- `messaging-collaboration-skills`: chat-app, bot, business-messaging, meeting-collaboration, iMessage collaboration, Communication Notifications, Push to Talk, VoIP/SIP, documented iOS/iPadOS default communication roles, and app-owned macOS client workflows for Discord, Telegram, Slack, Teams, WhatsApp Business, SMS/MMS/RCS, Google Meet, and Apple communication surfaces, with explicit Signal and Mac operator-automation boundaries
- `model-lab-skills`: reproducible language-model experiment design, dataset preparation, fine-tuning, evaluation, checkpoint comparison, representation and steering research, refusal ablation, authorized jailbreak and tool-calling evaluation, runtime benchmarking, and current-source routing across Core AI, Core ML, MLX, ExecuTorch, and Foundation Models
- `agentdeck`: local Codex runtime utilities, starting with hooks that prefix generated Codex thread titles with the project directory name
Expand All @@ -163,7 +163,7 @@ Current Socket catalog shape:
- `python-skills`: Python runtime and tooling workflows for Python-based projects; see the [Python skills expansion plan](./docs/maintainers/python-skills-plugin-plan.md) for maintainer details
- `reverse-engineering-skills`: artifact triage, preservation, exact-build comparison, decompiler review, Apple Mach-O/runtime/signing/Apple Silicon/dyld/dynamic/kernel research, Cutter/Rizin, Malimite, Ghidra, Hopper, .NET, Unity and IL2CPP, and reproducible security evidence workflows
- `server-side-jvm`: server-side JVM, Java, Scala, Gradle, Maven, SBT, and testing workflow guidance, with future Clojure support planned
- `server-side-swift`: server-side Swift bootstrap and guidance sync, Vapor, Hummingbird, hb Server/Lambda flows, persistence, OpenAPI/RPC, SwiftNIO, observability, auth, app sync, Docker, Apple Containerization, and Fly.io support plus the source-bundled `server-swift-steward` custom-agent definition
- `server-side-swift`: server-side Swift bootstrap and guidance sync, Vapor, Hummingbird, persistence, OpenAPI/RPC, SwiftNIO, observability, auth, app sync, Docker, Apple `container` 1.x, persistent `container machine` environments, exact-version Containerization APIs, and Fly.io support plus the source-bundled `server-swift-steward` custom-agent definition
- `swift-lang`: shared Swift language, API style, error handling, functional pipelines, formatting, source organization, SwiftSyntax transformation, compiler inspection, SourceKit semantics and indexing, SourceKit-LSP diagnosis, Swiftly/Xcode toolchain routing, and modernization cleanup workflows
- `rust-skills`: Rust, Cargo, rustup, crate, workspace, CLI, library, package, CI, test, lint, and format workflow guidance
- `speak-swiftly`: Git-backed Speak Swiftly plugin from the standalone SpeakSwiftlyServer repository
Expand Down
37 changes: 37 additions & 0 deletions ROADMAP.md
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,7 @@
- [Milestone 27: Cybersecurity skills plugin](#milestone-27-cybersecurity-skills-plugin)
- [Milestone 28: Swift language tooling expansion](#milestone-28-swift-language-tooling-expansion)
- [Milestone 29: Model Lab skills plugin](#milestone-29-model-lab-skills-plugin)
- [Milestone 30: macOS virtualization and container skills expansion](#milestone-30-macos-virtualization-and-container-skills-expansion)
- [Small Tickets](#small-tickets)
- [Backlog Candidates](#backlog-candidates)
- [History](#history)
Expand Down Expand Up @@ -73,6 +74,7 @@
- Milestone 27: Cybersecurity skills plugin - Planned
- Milestone 28: Swift language tooling expansion - In Progress
- Milestone 29: Model Lab skills plugin - Planned
- Milestone 30: macOS virtualization and container skills expansion - Completed

## Milestone 5: SwiftASB skills plugin

Expand Down Expand Up @@ -995,6 +997,41 @@ Implemented; release pending
- [x] Refusal ablation and jailbreak workflows measure ordinary behavior, regressions, and uncertainty in addition to bypass outcomes.
- [x] Root docs, marketplace wiring, Codex/Hermes/Claude compatibility, plugin metadata, and validation agree on the shipped inventory.

## Milestone 30: macOS virtualization and container skills expansion

### Status

Completed

### Scope

- [x] Record the cross-plugin architecture, ownership, source baseline, phased skills, security boundaries, validation, and forward-test plan in [`docs/maintainers/macos-virtualization-and-container-skills-plan.md`](./docs/maintainers/macos-virtualization-and-container-skills-plan.md).
- [x] Add Apple Dev selection and Virtualization framework foundations that distinguish host execution, OCI containers, persistent Linux machines, full Linux VMs, full macOS VMs, and physical Macs.
- [x] Expand the Apple Containerization workflow for the `container` 1.x CLI, persistent `container machine` environments, TOML configuration, structured-output changes, and exact-version 0.x Containerization package APIs.
- [x] Add separate Linux and macOS development-VM workflows instead of flattening their boot, identity, device, lifecycle, and fidelity contracts.
- [x] Add a Cybersecurity lab-preparation workflow that turns an isolation decision into verified mount, clipboard, credential, device, network, baseline, evidence-export, revert, and teardown controls.
- [x] Keep the expansion guidance-only: no VM images, restore images, kernels, malware samples, privileged helpers, daemons, guest agents, MCP servers, remote credentials, or automatic third-party tool installation.

### Planned Slices

- [x] Phase 1: add `apple-dev-skills:choose-macos-virtualization-shape` and `apple-dev-skills:virtualization-framework-workflow`, then align Cybersecurity isolation handoffs.
- [x] Phase 2: update `server-side-swift:apple-containerization-workflow` for `container` 1.x and add `apple-dev-skills:linux-development-vm-workflow`.
- [x] Phase 3: add `apple-dev-skills:macos-development-vm-workflow` with restore-image, VM-bundle, identity, clean-baseline, and reset guidance.
- [x] Phase 4: add `cybersecurity-skills:prepare-isolated-analysis-lab` and align dynamic-analysis and macOS-investigation workflows around its lab record.
- [x] Forward-test the ten planned stable guidance paths through scenario contract tests before adding any tool-specific adapter skill; treat Lima, Colima, Tart, UTM, VMware Fusion, Parallels Desktop, OrbStack, and similar products as discovered adapters until repeated tasks justify a dedicated surface.
- [x] Regenerate portable Hermes exports, update Claude and Cowork classifications, refresh root architecture metadata and user-facing inventory text, and run affected child plus root validation with each shipped phase.

### Exit Criteria

- [x] An agent selects a development or research boundary by required fidelity, persistence, portability, host integration, and threat model instead of choosing a familiar tool name first.
- [x] Apple `container`, `container machine`, full Linux VMs, and full macOS VMs have distinct owners and lifecycle contracts.
- [x] A custom Virtualization framework host validates guest configuration, entitlements, devices, lifecycle, and save/restore compatibility without calling saved state a full snapshot system.
- [x] macOS security-control claims use a macOS guest or physical Mac when Linux cannot reproduce the behavior, and remaining hardware or anti-VM gaps are explicit.
- [x] Security labs default ambient host authority to absent, preserve intended evidence through a narrow export, and verify revert or teardown after execution.
- [x] Socket's skill metadata, portability exports, compatibility records, documentation, and validation agree on the shipped virtualization inventory.

Completed Milestone 30 by shipping four Apple Dev virtualization workflows, a disposable Cybersecurity lab-preparation workflow, Apple `container` 1.x and `container machine` guidance, guest-versus-host evidence rules, Hermes exports, Claude and Cowork compatibility metadata, architecture inventory updates, and ten scenario-level forward tests. The rebased `9.19.0` release candidate preserves the concurrent Model Lab inventory and passed 268 Apple Dev tests, 126 Socket tests with one intentional skip, Apple and Cybersecurity child validators, Socket marketplace validation, Hermes parity, Claude/Cowork validation, and the architecture consistency check.

## Small Tickets

- [ ] Record issue-sized fixes, TODO/FIXME imports, and cleanup work that is too small or too unplanned for a milestone.
Expand Down
Loading