rdmsm4x-changelog-20260831-1817-fleet-tcc-privilege-audit-trigger
rdmsm4x-changelog-20260831-1817-fleet-tcc-privilege-audit-trigger
Audited and triggered missing TCC permissions, screen capture, full disk access, accessibility, automation, and developer taskport rights across AI agents and terminal applications on all 6 fleet hosts.
Scope
- Hosts:
rdmsm4x(lead),rdmbair15m5,rdmbair13m5,jdmbair13m5,rdmpw3265m,rdmpw3275m - Target Applications & Agents:
- AI Agents / Tools: Claude (
Claude.app,claude), Codex (codex,ChatGPT.app), Antigravity (Antigravity.app,agy), Antigravity IDE (Antigravity IDE.app,antigravity-ide,agy-ide), Grok / Grok Bot (grok,Grok Bot.app), Cursor (Cursor.app,cursor-agent,cursor), Ollama (ollama), Copilot. - Terminal Apps: Terminal (
Terminal.app), Ghostty (Ghostty.app), Warp (Warp.app,WarpPreview.app), Wave (Wave.app), AristaTerminal (AristaTerminal.app).
- AI Agents / Tools: Claude (
- Services:
- Screen Recording / Desktop View
(
kTCCServiceScreenCapture) - Full Disk Access (
kTCCServiceSystemPolicyAllFiles) - Accessibility / Computer Control
(
kTCCServiceAccessibility) - AppleEvents / Automation (
kTCCServiceAppleEvents) - Developer Tools & Taskport Debugging
(
DevToolsSecurity,authorizationdb system.privilege.taskport*,_developergroup)
- Screen Recording / Desktop View
(
Files Created / Touched
/Users/richh/dev/scripts/fleet_tcc_manager.zsh(Canonical script)~/scripts/fleet_tcc_manager.zsh(Deployed on all 6 hosts)~/dev/LLM/Claude/changelogs/rdmsm4x-changelog-20260831-1817-fleet-tcc-privilege-audit-trigger.md~/dev/SESSION-STATE.md&~/.agent-coordination/SESSION-STATE.md- Ticket
SEC-20260831-08in~/dev/issues/
Actions & Execution
- Developer Mode & Taskport Debugging: Ran
preauthorize_dev_permissions.zshon all 6 hosts, ensuring Developer Mode is active,system.privilege.taskport+system.privilege.taskport.debug+system.privilege.taskport.safeare set toallow, and_developergroup membership containsrichhandjoey. - App & Binary Discovery: Probed all
/Applications,/Applications/Utilities,~/Applications, Homebrew prefixes, and local bin paths on each node. - Privilege Audit & Triggers:
- Screen Recording: Invoked
CGRequestScreenCaptureAccess()across nodes to prompt/register applications. - Accessibility: Invoked
AXIsProcessTrustedWithOptionswithkAXTrustedCheckOptionPrompt: trueto trigger system authorization dialogs where needed. - AppleEvents: Verified AppleEvents / Automation execution
(
osascript). - Full Disk Access: Probed protected system paths and opened System
Settings Privacy panels (
Privacy_ScreenCapture,Privacy_Accessibility,Privacy_AllFiles,Privacy_Automation,Privacy_DevTools) on GUI sessions.
- Screen Recording: Invoked
Verification Evidence
- Developer Mode: Enabled on 6/6 hosts.
- Taskport Authorization Rule:
allowverified on 6/6 hosts. - AppleEvents / Automation: Granted and functional across 6/6 hosts.
- Accessibility & Screen Capture Triggers: Executed and primed on 6/6 hosts.
- Privacy Panes: Opened on active GUI sessions to allow immediate verification of any pending toggles.
Outstanding Owner Actions
- In macOS
System Settings > Privacy & Security:- Verify that
Antigravity,Antigravity IDE,Claude,ChatGPT,Cursor,Ghostty,Terminal, andWarphave their checkboxes enabled under Full Disk Access, Accessibility, and Screen Recording.
- Verify that
How to Undo
- Taskport rights can be restored to default via:
sudo security authorizationdb remove system.privilege.taskport - TCC permissions can be reset for any bundle ID via:
tccutil reset <Service> <bundle_id>