macOS 27 integration costs two system protections
Using Claude for Siri on macOS 27 requires disabling both System Integrity Protection and AMFI. A prompt chosen through Spotlight's native Ask menu then reaches your existing Claude Code account. The extension passes the text to a Swift bridge on 127.0.0.1:17839, the bridge launches the Claude CLI, and streamed text returns to Apple's response UI. You get a native-looking provider without another web account or a remote bridge service run by this project.
The price is high. The setup also needs Xcode 27 and XcodeGen. Both the host app and provider extension carry a private model-delegation entitlement and are ad-hoc signed. Apple does not grant a distributable entitlement through this setup. The maintainer calls it experimental and says to use a development Mac. That warning should decide where you install it.
Installation builds Claude.app under ~/Applications, verifies its signature, backs up an earlier copy of the same example, and refuses to replace an unrelated app at that path. Anthropic's app under /Applications is separate. The script then registers and opens the new bundle. This is careful handling for a research installer, but it does not turn private beta APIs into a stable deployment surface.
Text reaches Claude Code with tools switched off
One Spotlight request creates one fresh Claude conversation, with tools and MCP servers disabled. The runner also disables Chrome integration and conversation persistence. It uses a private temporary directory, deletes the prompt after execution, and does not log prompts, replies, or credentials. Those choices stop a Spotlight question from silently becoming a general agent session with access to your working directories.
The extension is sandboxed; the host stays outside that sandbox so it can launch the CLI. A random bearer token authenticates traffic between them. The server listens only on IPv4 loopback, rejects browser Origin headers and ambiguous HTTP framing, and places limits on request size, connections, parallel Claude processes, and execution time. Another local process that can read the application bundle can also read the token, so the README correctly avoids calling it a local security boundary.
Capabilities are narrower than the native sheet may suggest. The provider accepts text and streams text back. It does not accept attachments, make images, run device actions, or read mail, contacts, messages, and Siri's semantic index. Every new Ask action forgets the prior exchange. That is a sensible research scope, but it is a poor fit for anyone expecting a voice assistant or a persistent Claude chat.
What happened when we ran it
We did not run commit d29408a because our sandbox does not support the repository's Swift ecosystem. There is also no Dockerfile that could turn the fresh Debian container into the macOS 27 and Xcode 27 environment required by the build scripts. No install, build, test, dependency, or vulnerability result should be inferred from this review.
The repository does contain a Swift package test target, a local smoke script, and troubleshooting commands for Claude authentication, PlugInKit registration, code signing, and the loopback port. Those are statements about the checked-in project and README, not results from our lab. A useful local acceptance pass would need the intended macOS build, the private entitlement behavior, native consent, explicit Spotlight selection, one streamed reply, and successful restoration of normal discovery.
This distinction matters more here than it would for an ordinary command-line package. Compiling the bridge alone cannot show that Siri-related services discover the provider, consent is presented, or Apple's UI routes a prompt. The README itself separates a successful bridge request and provider discovery from the still-needed manual check of a full native Spotlight conversation with the current app build.
Explicit Spotlight selection works, default Siri routing does not
The verified user route is Command-Space, right-click the input, choose Ask... -> Claude, and complete Apple's Turn On flow if prompted. There is no verified system-wide setting that makes this custom extension the default Ask provider. Selecting Claude once does not establish that a later Spotlight window or an ordinary Siri request will choose it. Voice routing remains unverified.
Discovery needs a temporary runtime shim because the tested macOS 27 build filters third-party providers. The shim changes an internal-UI query only inside selected Siri-related processes and supplies expanded discovery for those processes. Starting it requires administrator authentication and restarts affected services. Stopping it restores their normal launch settings, while a reboot also ends the temporary session. The app provides both Enable in Spotlight and Restore Normal Discovery controls.
The discovery notes record an input-focus problem observed during experimentation, though they do not establish that the shim caused it. Spotlight, Siri's separate Ask menu, and System Settings may also show different provider lists because they use distinct discovery or caching paths. That uncertainty is enough to keep the app off a machine you rely on for normal Siri and Spotlight behavior.
September code activity has not produced a release
GitHub showed 225 stars and no open issues or pull requests. Two small community pull requests were merged on September 15, 2026, the same date as the last code push. There is no tagged release, and the repository was created only the day before. A quiet open queue here means there is little reported history, not that private provider discovery has become settled.
The README is better than most experimental projects at naming what has and has not been proved. It documents the security reduction, private entitlement, rollback, account path, text-only boundary, token weakness, and unverified native behaviors. That makes the repository useful to a Swift developer studying Apple's model-delegation work. It does not make the app a sensible shortcut for someone who just wants Claude near the Spotlight bar.
