Lock down a macOS app with a sandbox profile

Generates a minimal Seatbelt sandbox config that restricts app permissions to only what it needs—file access, network, system calls—with an allowlist approach.

Best for: Engineers hardening a macOS app or enforcing least-privilege access controls.

Engineering / debugging-investigationatomicfor-engineersno-setupfrom-text

Topics

agent-skills

Source

Creator's repository · trailofbits/skills

View on GitHub

License: CC-BY-SA-4.0