Skip to main content
Glama
badchars

living-off-the-land-lolbins-mcp-server

by badchars

find_macos_tcc_bypass

Discover macOS TCC bypass techniques such as entitlement abuse, SIP circumvention, and Gatekeeper bypass to test security permissions.

Instructions

Find macOS TCC (Transparency, Consent, and Control) bypass techniques — TCC bypass, entitlement abuse, SIP circumvention, Gatekeeper bypass.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
modeNomacOS security bypass typebypass
environment_idNoEnvironment session ID
target_permissionNoTarget TCC permission: full_disk_access, camera, microphone, screen_recording
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries full burden. It only lists target areas and does not disclose behavior such as whether it reads data, requires authentication, or has side effects. The agent lacks information about prerequisites or return format.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is concise, using a single line with a parenthetical list to enumerate technique types. It is front-loaded with the core purpose. However, it could be more structured with separate sentences for clarity.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The description is incomplete for a tool with no output schema. It does not explain what the tool returns (e.g., list of techniques, details, or commands). Parameters like 'environment_id' and 'target_permission' lack usage context. The agent cannot fully understand how to invoke the tool effectively.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% with descriptions for all three parameters. The description adds a list of technique types that correspond to the 'mode' enum, but does not clarify the role of 'environment_id' or 'target_permission' beyond schema. This meets baseline but does not exceed it.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool finds macOS TCC bypass techniques and lists specific types (bypass, entitlement abuse, SIP circumvention, Gatekeeper bypass). It uses a specific verb 'find' with a well-defined resource, distinguishing it from sibling tools like find_dll_hijack or find_process_manipulation.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies the tool is used to find macOS TCC bypasses but does not explicitly state when to use it vs. alternatives like 'search_techniques' or other find_* tools. No exclusion criteria or context is provided, leaving the agent to infer usage from the tool name and description.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Install Server

Other Tools

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/badchars/living-off-the-land-lolbins-mcp-server'

If you have feedback or need assistance with the MCP directory API, please join our Discord server