Apple Notes Sdk PatternsBLOCK
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: apple-notes-sdk-patterns description: 'Apply production-ready patterns for Apple Notes JXA/AppleScript automation. Trigger: "apple notes patterns". ' allowed-tools: Read, Write, Edit, Bash(osascript:*), Grep version: 1.6.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - macos - apple-notes - automation compatibility: Designed for Claude Code --- # Apple Notes SDK Patterns ## Overview Production patterns for Apple Notes automation: JXA wrapper class, error handling, batch operations, and cross-account support. ## Prerequisites - A scoped account/folder configuration resolved outside the JXA source string. - A safe process invocation boundary that passes source and data without shell interpolation. - Durable idempotency tracking for writes and a synthetic local test corpus. ## Instructions 1. Treat names, bodies, queries, and folder identifiers as data—not template fragments or shell arguments. 2. Resolve only explicitly configured accounts and folders, and fail if the target is absent rather than creating it implicitly. 3. Keep list and search results scoped and minimize returned fields; never log note bodies by default. 4. Serialize mutations, record an opaque idempotency key before the call, and reconcile timeouts before retrying. ## Procedure ### Step 1: JXA Client Wrapper (Node.js) ```typescript // src/notes-client.ts import { execSync } from "child_process"; class AppleNotesClient { private runJxa(script: string): string { const escaped = script.replace(/'/g, "\\'"); return execSync(`osascript -l JavaScript -e '${escaped}'`, { encoding: "utf8", timeout: 30000, }).trim(); } listNotes(folder?: string, limit: number = 50): Array<{ id: string; title: string; modified: string }> { const script = folder ? `const Notes = Application("Notes"); const f = Notes.defaultAccount.folders().find(f => f.name() === "${folder}"); (f ? f.notes() : []).slice(0, ${limit}).map(n => JSON.stringify({id: n.id(), title: n.name(), modified: n.modificationDate().toISOString()})).join("\\n")` : `const Notes = Application("Notes"); Notes.defaultAccount.notes().slice(0, ${limit}).map(n => JSON.stringify({id: n.id(), title: n.name(), modified: n.modificationDate().toISOString()})).join("\\n")`; return this.runJxa(script).split("\n").filter(Boolean).map(l => JSON.parse(l)); } createNote(title: string, body: string, folder?: string): string { const folderPart = folder ? `let f = account.folders().find(f => f.name() === "${folder}"); if (!f) { f = Notes.Folder({name: "${folder}"}); account.folders.push(f); }` : "let f = account.folders[0];"; return this.runJxa(` const Notes = Application("Notes"); const account = Notes.defaultAccount; ${folderPart} const note = Notes.Note({name: ${JSON.stringify(title)}, body: ${JSON.stringify(body)}}); f.notes.push(note); note.id(); `); } searchNotes(query: string): Array<{ title: string; folder: string }> { const result = this.runJxa(` const Notes = Application("Notes"); const q = "${query}".toLowerCase(); Notes.defaultAccount.notes().filter(n => n.name().toLowerCase().includes(q) || n.body().toLowerCase().includes(q) ).slice(0, 20).map(n => JSON.stringify({title: n.name(), folder: n.container().name()})).join("\\n"); `); return result.split("\n").filter(Boolean).map(l => JSON.parse(l)); } } export { AppleNotesClient }; ``` ### Step 2: Batch Operations with Throttling ```typescript async function batchCreateNotes( client: AppleNotesClient, notes: Array<{ title: string; body: string; folder?: string }>, delayMs: number = 500, ): Promise<string[]> { const ids: string[] = []; for (const note of notes) { const id = client.createNote(note.title, note.body, note.folder); ids.push(id); await new Promise(r => setTimeout(r, delayMs)); } return ids; } ``` ## Output - Type-safe JXA client wrapper for Node.js - List, create, search operations via osascript - Batch operations with throttling ## Error Handling If source generation, JSON parsing, or an Apple Event call fails, retain the opaque operation key and return a redacted error category. Do not retry a create until the scoped target has been checked for the prior operation. Reject unconfigured folders, over-limit requests, and any input that would require shell-string interpolation. ## Examples For a synthetic import, resolve the test folder from reviewed configuration, enqueue one record with a source-record key, and verify its returned opaque identifier before advancing. For production, use a process API with argument arrays or stdin rather than the illustrative interpolated `execSync` command strings above; keep the adapter implementation in a reviewed module. ## Resources - [Mac Automation Scripting Guide](https://developer.apple.com/library/archive/documentation/LanguagesUtilities/Conceptual/MacAutomationScriptingGuide/) - JXA Examples
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (1)
return execSync(`osascript -l JavaScript -e '${escaped}'`, {Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__apple-notes-sdk-patterns.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | BLOCK | D | 69 | first audit |
Questions
What does the Apple Notes Sdk Patterns skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Apple Notes Sdk Patterns safe to install?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What can Apple Notes Sdk Patterns access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Apple Notes Sdk Patterns work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.