macos-cis-scan v0.1.0
Initial public release of a read-only NIST mSCP CIS audit wrapper.
Included
scan_cis.zsh— CIS Level 1 or Level 2 audit wrapper.SHA256SUMSandSHA256SUMS.sig— integrity manifest and detached SSH
signature.r4kh1m-release-signing-key.pub— public key for manifest verification.
The release-signing key fingerprint is:
SHA256:Rt9xlHKnOMVeREiwG041268qY0kxu72vYVt+CntuF+4
Compatibility
macOS 14, 15, and 26 are accepted. The release was end-to-end tested on macOS
26 Apple Silicon. See Compatibility before using it on a
different target.
Safety contract
The generated mSCP audit is invoked only with --check. This release does not
run remediation commands.
Feedback
Use Discussions for questions and compatibility experience, Issues for
reproducible bugs, and GitHub private vulnerability reporting for security
findings. Never post an unredacted audit report.