Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Permission Scope Audit

ASecurity

Detects over-broad permission requests where a narrower permission or privacy-preserving alternative API is sufficient, violating Guideline 5.1.1(iii) data minimization requirements.

18 stars
0 votes
0 copies
1 views
Added 9/20/2026
developmentgophpswiftbashreactapi

Works with

api

Security Analysis

A100/100

Scanned 9/20/2026

Install to Claude Code

$npx -y skills add cruisediary/apple-app-review-skills --skill permission-scope-audit --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Permission Scope Audit?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Permission Scope Audit
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/cruisediary-permission-scope-audit/badge)](https://www.skillsdirectory.com/skills/cruisediary-permission-scope-audit)

More formats (shields.io, HTML) on the badges page.

Download with Pro
Files
SKILL.md
---
name: permission-scope-audit
description: "Detects over-broad permission requests where a narrower permission or privacy-preserving alternative API is sufficient, violating Guideline 5.1.1(iii) data minimization requirements."
---

# Skill: Permission Scope Audit
<!-- SEO: over-broad permission always location full photo library contacts data minimization scope iOS App Store rejection -->

## Purpose
Detects over-broad permission requests where a narrower permission or privacy-preserving alternative API is sufficient, violating Guideline 5.1.1(iii) data minimization requirements.

## Apple Guideline
- **Primary:** 5.1.1(iii) — Data Collection and Storage: Accessing User Data — Data Minimization
- **Related:** 5.1.1(ii), 5.1.2
- **Reference:** `references/guidelines/5-legal.md`

## Real-World Rejection Cases
- **Case:** App requested Always location when WhenInUse was sufficient — reviewer flagged over-collection
  **Source:** Apple Developer Forums, multiple threads
  **Root cause:** Always location requires explicit justification (navigation, fitness tracking, delivery); requesting it for simple map display violates data minimization — reviewers check that the scope of the requested permission matches the declared use case

## Trigger
Invoke on any iOS/macOS project to detect permission scope mismatches and suggest privacy-preserving alternative APIs.

## Inputs
| Name | Type | Default | Description |
|------|------|---------|-------------|
| `project_root` | path | cwd | iOS/macOS project root |
| `shared_context` | object | nil | Pre-collected context from appstore-full-audit Phase 1 |

## Actions

### Phase 1: Context Collection
*Skip this phase if `shared_context` is provided.*

1. `Glob` `**/*.swift` — collect all Swift source files.
2. `Glob` `**/*.m` — collect Objective-C source files.
3. `Glob` `**/Info.plist` — locate Info.plist.
4. `Glob` `**/*.entitlements` — locate entitlement files (check background location entitlement).

### Phase 2: Checks

1. **Always location permission scope**
   `Grep` pattern `requestAlwaysAuthorization` in `**/*.swift` and `**/*.m`.
   If found, `Read` surrounding context and check for navigation, fitness, delivery, or background tracking use case. If app category does not clearly require background location (e.g., simple map display, location tagging for posts), flag → 🟠 HIGH. Also `Grep` `com.apple.location.always` in `**/*.entitlements` — if entitlement absent but `requestAlwaysAuthorization` called → 🟠 HIGH.

2. **Full photo library access when only selection needed**
   `Grep` pattern `PHPhotoLibrary.*requestAuthorization.*readWrite` in `**/*.swift`.
   If found without accompanying `PHPickerViewController` usage (`Grep` `PHPickerViewController` in `**/*.swift`), flag → 🟠 HIGH. PHPickerViewController provides privacy-preserving photo selection without requiring full library authorization.

3. **Full contacts access when only picker needed**
   `Grep` pattern `CNContactStore.*requestAccess|requestAccess.*forEntityType.*contacts` in `**/*.swift` and `**/*.m`.
   If found, `Read` surrounding context. If app only needs to select an email or phone number (not programmatic contact access), suggest `CNContactPickerViewController` which requires no permission → 🟠 HIGH.

### Phase 3: Output
Collect all findings from Phase 2 and build the prioritised findings list below. Include file paths and line numbers. Omit tiers with no findings.

## Output Format

```
## Permission Scope Audit — Findings

### 🔴 CRITICAL — Guaranteed rejection
- [ ] TODO: <exact actionable step> — `file:line` — Guideline 5.1.1(iii)

### 🟠 HIGH — Very likely rejection
- [ ] TODO: Replace requestAlwaysAuthorization with requestWhenInUseAuthorization — background location is not justified for this app's stated purpose — `LocationManager.swift:34` — Guideline 5.1.1(iii)
- [ ] TODO: Replace PHPhotoLibrary.requestAuthorization(.readWrite) with PHPickerViewController — no full library access needed for profile photo selection — `ProfileViewController.swift:67` — Guideline 5.1.1(iii)
- [ ] TODO: Replace CNContactStore.requestAccess with CNContactPickerViewController — system contact picker requires no permission and is privacy-preserving — `ContactsManager.swift:21` — Guideline 5.1.1(iii)

### 🟡 MEDIUM — Possible rejection
- [ ] TODO: Verify Always location entitlement is present in .entitlements file if requestAlwaysAuthorization is intentionally used

### 🟢 LOW — Best practice
- [ ] TODO: Audit all permission requests against Apple's privacy-preserving API alternatives (PHPickerViewController, CNContactPickerViewController, CLLocationButton)
```

## Tools Used
`Glob`, `Grep`, `Read`

## Constraints
- Read-only. No file edits.
- No network calls.
- Skip Phase 1 if `shared_context` is provided by orchestrating agent.
- Works on Swift, Objective-C, React Native, Flutter projects.

## Quick Commands

Run these in your project root to check manually:

```bash
# Check for Always location (high scrutiny permission)
!grep -rn "requestAlwaysAuthorization" . --include="*.swift"

# Check for full photo library access vs picker
!grep -rn "PHPhotoLibrary.requestAuthorization\|PHPickerViewController" . --include="*.swift"

# Check for full contacts access vs picker
!grep -rn "CNContactStore\|CNContactPickerViewController" . --include="*.swift"
```

## Swift Anti-Pattern Reference
`examples/swift/PermissionPatterns.swift`

## Detection Steps

1. **Find target files**
   - Glob: `**/*.swift`, `**/*.m`, `**/Info.plist`

2. **Search for rejection patterns**
   - Grep `requestAlwaysAuthorization` — always-on location (highest scope)
   - Grep `requestWhenInUseAuthorization` — when-in-use location (acceptable default)
   - Grep `CNContactStore.*requestAccess` + absence of `CNContactPickerViewController` — full contacts vs picker
   - Grep `PHPhotoLibrary.requestAuthorization` + absence of `PHPickerViewController` — full library vs picker
   - Read `Info.plist` → check if both `NSLocationWhenInUseUsageDescription` and `NSLocationAlwaysUsageDescription` present

3. **Determine verdict**
   - `requestAlwaysAuthorization` for non-navigation/fitness app → 🟠 HIGH (Guideline 5.1.1(iii))
   - Full `CNContactStore` access when picker would suffice → 🟠 HIGH
   - Full photo library access when `PHPickerViewController` would suffice → 🟠 HIGH
   - Minimum necessary scope used for each permission → 🟢 pass

4. **Report**
   - File path + line of over-scoped permission request
   - Fix: Use `requestWhenInUseAuthorization` unless navigation tracking is core; use `CNContactPickerViewController` and `PHPickerViewController` instead of direct library access

Attribution

cruisediarycruisediary
View sourceMore from cruisediary →
SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Related Skills

Browser Extension Developer

Use this skill when developing or maintaining browser extension code in the `browser/` directory, including Chrome/Firefox/Edge compatibility, content scripts, background scripts, or i18n updates.

284972 votes

Seo Optimizer

SEO optimization with keyword analysis, readability assessment, technical validation, content quality. Use for search rankings, blog posts, content audits, or encountering keyword density, readability scores, meta tags, schema markup errors.

2192 votes

Google Official Seo Guide

Official Google SEO guide covering search optimization, best practices, Search Console, crawling, indexing, and improving website search visibility based on official Google documentation

1862 votes

Tanstack Start

Build a full-stack TanStack Start app on Cloudflare Workers from scratch — SSR, file-based routing, server functions, D1+Drizzle, better-auth, Tailwind v4+shadcn/ui. Use whenever the user mentions TanStack Start, asks to scaffold a full-stack Cloudflare app with SSR, wants an SSR dashboard, or asks for a React 19 + Cloudflare Workers app with file-based routing and server functions — even if they don't name TanStack Start specifically. No template repo — Claude generates every file fresh per ...

10311 votes

Pentest

PTES-aligned adversarial security audit for backend, frontend, and mobile applications. Produces a CVSS-scored Hacker Report with verified PoCs and phased remediation.

5491 votes
View all in development →