Pinned
mac-posture-audit (MPA) v1.6 is out.
The new release asks one uncomfortable question:
If a poisoned package, MCP server, or AI-agent instruction file ran on your Mac, what could it reach?
183 read-only checks. One Bash file. No network.
mac-posture-audit v1.2 is out.
It now also audits the supply-chain surface on your Mac: browser + editor extensions and MCP servers, matched against a deny-list you control.
Read-only. Single shell file. No deps.
github.com/demirelo/mac-p…












