Skip to content
Back to skills

Install Cli Tools

ASecurity

Plan an owner-confirmed iOS and Expo CLI toolchain without exposing account credentials or running remote installer scripts. Use when the user says 'install CLIs', 'install eas cli', 'install fastlane', or 'install ios cli tools'.

  • 3 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 4, 2026
developmentshellbashnodetestinggit

Works with

  • cli

Security analysis

A96/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro scans all 2 files and shows the line behind each finding

Scanned October 4, 2026

npx -y skills add khadinakbarlabs/expo-mobile-app-builder --skill install-cli-tools --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Install Cli Tools?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Install Cli Tools
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/khadinakbarlabs-install-cli-tools/badge)](https://www.skillsdirectory.com/skills/khadinakbarlabs-install-cli-tools)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: "install-cli-tools"
description: "Plan an owner-confirmed iOS and Expo CLI toolchain without exposing account credentials or running remote installer scripts. Use when the user says 'install CLIs', 'install eas cli', 'install fastlane', or 'install ios cli tools'."
---

# Install iOS and Expo CLI Tools

These tools can alter a development machine or open provider login flows. Present the exact selected tools, their source, and their side effects before installing anything. Never pipe a network download into a shell.

## External action gate

Installing tools, running provider logins, creating credentials, and configuring EAS can change a machine or external account. Do not perform them until the owner confirms the selected tool, installation source, target account, and intended action.

## Common local tools

| Tool | Purpose | Safer installation boundary |
|---|---|---|
| EAS CLI | Expo build and submit tooling | Approved Node package manager |
| Fastlane | Apple automation | Approved system package manager |
| Sentry CLI | Source-map and release operations | Approved system package manager |
| Maestro | Mobile E2E testing | Official package-manager tap or verified release artifact |
| GitHub CLI | Repository operations | Approved system package manager; `gh auth login` needs owner confirmation |

For an explicitly approved macOS/Homebrew setup, install only the tools needed for the current project:

```bash
npm install -g eas-cli
brew install fastlane
brew install getsentry/tools/sentry-cli
brew tap mobile-dev-inc/tap
brew install maestro
brew install gh
```

Run provider logins, credential setup, `eas credentials`, builds, and uploads only after a separate confirmation names the target account and intended action.

## Verify

```bash
eas --version
fastlane --version
sentry-cli --version
maestro --version
gh --version
```

## Credential handling

- Never save Apple `.p8` files, EAS tokens, Sentry tokens, or provider keys in this plugin, a public repository, shell history, or screenshots.
- Use the provider's owner-controlled login or secret-storage flow. Do not ask a user to paste a credential into chat.
- Prefer least-privilege, project-scoped credentials and rotate/revoke them when access changes.

Files in this skill

  • SKILL.md2.2 KB
  • agents/openai.yaml182 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…