vibe coded with ❤️
Concept app · v0.2.0 · Notarized

Lynceus

A security review of everything that runs through your Jamf Pro: scripts, extension attributes, policy commands and script parameters, local accounts in policies, configuration profiles and package scripts. Lynceus reads them live with read-only API requests or offline from Gimle backups. A local AI reviews each object first, then 39 deterministic rules confirm, add and check what the model claims. You get an executive summary, a security report and a fix list for engineers.

Concept app. Lynceus explores whether a small local AI, kept honest by deterministic rules, can give a Jamf Pro team a useful security review of everything it deploys. Version 0.2.0 is signed and notarized. It has been tested in a demo environment only, not against a production Jamf Pro, so treat its findings as a starting point for your own review. Named after the Argonaut who could see through walls.
Lynceus showing the findings of a second scan of the demo tenant Demo Corp: risk grade E, 18 high and 10 medium findings, 2 new and 6 fixed since the last scan, and a hardcoded credential with its masked code in the inspector

See through every script you deploy

🔍

Everything That Runs

Scripts, script-type extension attributes, policy Files & Processes commands, script parameters $4–$11 and local accounts, computer and mobile device configuration profiles, and pre/postinstall scripts from packages in Gimle backups.

🧠

AI First, Rules Second

The bundled Gemma 4 model reads each object like a reviewer. Then 39 rules (30 security, 6 hygiene, 3 deprecation) run. A finding both agree on is confirmed. An AI finding that quotes code which doesn't exist is marked unverified and doesn't count. The AI alone never rates a finding critical.

👁️

Read-Only

Live scans only send GET requests, through Gimle's backup engine, so a read-only API role is enough. Or skip the API entirely and scan a Gimle backup, encrypted ones included.

🔒

Secrets Masked

Passwords, tokens and keys found in your content are masked everywhere Lynceus stores or shows them: findings, history, logs and every report. The tests check the reports for leaks.

📑

Three Reports

An executive summary (risk grade, top risks, trend), a security report (every finding with evidence, coverage, accepted risks, the rule set used) and a fix list for engineers, as PDFs, plus CSV and Markdown.

🔁

New and Fixed

Every scan is kept, so each run shows what's new and what's fixed. Unchanged objects aren't sent to the AI again. Accept a risk or mark a false positive with a reason; accepted risks reopen after 180 days by default.

📍

What's Actually Deployed

Per object: is it in use, which policies use it, and how many devices it reaches. First seen and last changed come from the Gimle backup history. Filter to what's in use and fix that first.

✅

Triage in Bulk

Group findings by object or by finding, select several with ⌘-click, ⇧-click or ⌘A, and accept, dismiss or reopen them in one step.

🎯

Scope Before a Scan

Skip an object or check it with rules only, each with a reason. The scope applies to every later scan, and the reports list what was left out. A skipped object never counts as fixed.

📐

Your Own Rules

Turn built-in rules off or change their severity, write custom rules as regular expressions with a live test, and share them as JSON. MDM can deploy one rule set and lock editing.

⏱️

Live Progress

Watch a scan: progress, time left, the object under review and its stage, and the findings so far. If the AI fails, the scan pauses and retries every minute, and a stopped scan resumes where it left off.

🛡️

Local AI, Managed Options

The AI runs on the Mac by default. If a larger model is worth it, an admin can point Lynceus at the company's own OpenAI-compatible server through MDM. Secrets are masked before anything is sent, and AI can be turned off for rules-only scans. No telemetry.

Admin Guide

The read-only API role, scanning Gimle backups, managed preferences, the AI options, how findings are verified and scored, and where Lynceus keeps its data.

📖 Read the Documentation

Where things stand

System Requirements

macOS 27 or later, Apple Silicon only.

The bundled model needs about 2.7 GB of free memory; on an 8 GB Mac, close other apps before a scan.

For live scans: a Jamf Pro API client with a read-only role.

Build Status

Version 0.2.0. Signed with a Developer ID certificate and notarized by Apple. The 2.7 GB package includes the Gemma 4 E2B model (Apache 2.0).

54 unit tests pass in 17 suites (Swift 6, strict concurrency).

What's Verified

Tested in a demo environment only, not against a production Jamf Pro. The AI review was checked against the real bundled model on demo scripts. Pausing and retrying when the AI fails was tested end to end with a local fake server.

Why It Exists

Years of scripts pile up in every Jamf Pro: passwords in clear text, downloads run as root, security controls switched off. Lynceus finds them and shows which ones still reach devices.

Want to try the concept?

Concept app · Free · Signed & Notarized · macOS 27+ · Apple Silicon · 2.7 GB

Download Lynceus