smithery/benjaminshafii

openwork-notary

Store Apple notarization IDs in Keychain and notarize/staple OpenWork DMGs locally.

Installation

$ npx skills add smithery/benjaminshafii --skill openwork-notary

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from smithery/benjaminshafii.

npx skills add smithery/benjaminshafii

Browse all from smithery/benjaminshafii

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Declared

Skill metadata

Parsed from SKILL.md frontmatter.

Declared agents opencode

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 2,849 B
  • docs SUMMARY.md 106 B

History

  1. First recorded snapshot · 0 installs

SKILL.md

What this is

A small helper skill for the OpenWork macOS release flow.

It stores the App Store Connect Issuer ID, API Key ID, and .p8 path in the macOS Keychain so you don’t have to keep hunting them.

Keychain locations used by OpenWork release skills:

Notary credentials

  • Service: com.differentai.openwork.notary
  • Accounts:

- issuer-id - key-id - key-path

Tauri updater signing keys

These are used to sign updater artifacts (required for in-app updates).

  • Service: com.differentai.openwork.updater
  • Accounts:

- updater-private-key - updater-public-key

Quick usage (Keychain)

Store values

security add-generic-password -a issuer-id -s com.differentai.openwork.notary -w "<ISSUER_UUID>" -U
security add-generic-password -a key-id    -s com.differentai.openwork.notary -w "<KEY_ID>" -U
security add-generic-password -a key-path  -s com.differentai.openwork.notary -w "/path/to/AuthKey_<KEY_ID>.p8" -U

Read values

security find-generic-password -a issuer-id -s com.differentai.openwork.notary -w
security find-generic-password -a key-id    -s com.differentai.openwork.notary -w
security find-generic-password -a key-path  -s com.differentai.openwork.notary -w

Notarize + staple an OpenWork DMG (local)

1) Build a Developer ID signed DMG

APPLE_SIGNING_IDENTITY='Developer ID Application: Different AI inc. (F5DJWB4CCV)' \
  pnpm -C vendor/openwork exec tauri build --bundles dmg

2) Submit to Apple notarization (wait)

bun .opencode/skill/openwork-notary/first-call.ts

3) Staple and verify

DMG_PATH="vendor/openwork/src-tauri/target/release/bundle/dmg/OpenWork_0.1.2_aarch64.dmg"

xcrun stapler staple "$DMG_PATH"
spctl --assess --type open --verbose=4 "$DMG_PATH"

GitHub Actions: updater signing secret

The OpenWork release workflow expects a GitHub Actions secret:

  • TAURISIGNINGPRIVATE_KEY

To populate it from Keychain:

security find-generic-password -a updater-private-key -s com.differentai.openwork.updater -w

Then paste that value into the repo secret TAURISIGNINGPRIVATE_KEY.

Notes:

  • Do not commit the private key.
  • If you rotate/replace the private key, you must also update the embedded pubkey in vendor/openwork/src-tauri/tauri.conf.json to match.

Common gotchas

  • spctl saying Unnotarized Developer ID means signing is fine but notarization is missing.
  • codesign ... code has no resources but signature indicates they must be present usually means the .app bundle got signed incorrectly (or was modified after signing).
  • Apple notarization can take > 1h sometimes; don’t assume it’s broken immediately.