diff --git a/memory/memories.db b/memory/memories.db index eba9a4ac7..fc3976c1c 100644 Binary files a/memory/memories.db and b/memory/memories.db differ diff --git a/skills/mac-server-setup/SKILL.md b/skills/mac-server-setup/SKILL.md index b3e987031..2c88476af 100644 --- a/skills/mac-server-setup/SKILL.md +++ b/skills/mac-server-setup/SKILL.md @@ -103,6 +103,8 @@ before running. The script is idempotent — safe to re-run. Structure: - Shell aliases + starship init in .zshrc (idempotent) **Part 2 — Server hardening** (details: [references/hardening.md](references/hardening.md)) +- FileVault: disable (blocks unattended boot) +- Auto-login: enable for server user (kcpassword + loginwindow pref) - Power: no sleep, auto-restart on power loss - App firewall: on, allow signed, stealth mode - SMB: disable guest access @@ -302,7 +304,8 @@ full checklist. - SSH MCP servers typically can't sudo — generate script, user runs it - `launchctl disable gui/$UID/