gatekept
Runs a read-only macOS security scan for suspicious signatures, persistence, and malware traces.
- Stars
- 0
- Forks
- 0
- Updated
- Updated Jun 30, 2026
Runs a read-only macOS security scan for suspicious signatures, persistence, and malware traces.
gatekept verifies macOS application signatures with Apple’s codesign and spctl, flagging ad-hoc or unknown signers, injected dylibs, sideloaded apps, and Gatekeeper rejections. It also checks LaunchAgents, LaunchDaemons, Login Items, cron, shell startup files, temporary payloads, and hardening posture, then opens a self-contained local HTML report. The scan needs no account or dependency and does not modify the machine.
Resource types
Use cases
Platforms
Scan Agent Skills for injection, exfiltration, and malicious code patterns.
Connect to GlobalProtect VPNs on Linux through a CLI or GUI.
Operating systems
Runtime
Capabilities
Audience
Public GitHub facts last synced Jul 10, 2026.
Scan Electron applications for insecure settings and implementation anti-patterns.
Scan agent skills with static checks, semantic review, and sandbox execution.