choose-macos-virtualization-shapelisted
Install: claude install-skill gaelic-ghost/socket
# Choose macOS Virtualization Shape
## Purpose
Choose one boundary from evidence about fidelity, persistence, portability, host integration, threat level, and resources. Produce the shared shape record in [virtualization-shape-record.md](references/virtualization-shape-record.md); do not return an undecided product menu.
## When To Use
- Use for macOS-hosted development, clean-state validation, Linux compatibility, custom VM tools, and security-lab boundary selection.
- Use when container, persistent Linux machine, full VM, and physical Mac terminology is being mixed.
- Use before `virtualization-framework-workflow`, either development-VM workflow, or `prepare-isolated-analysis-lab` when the boundary is not already approved.
## Single-Path Workflow
1. Record the purpose, host, target OS and architecture, GUI/headless needs, privileges, kernel/devices, expected lifetime, and evidence requirements.
2. Classify fidelity and risk:
- trusted native macOS behavior: host process
- one portable Linux application: OCI container
- Apple-native per-container VM runtime: Apple `container`
- persistent OCI-backed Linux environment with services: `container machine`
- custom kernel, boot, disk, full-system, or GUI Linux: full Linux VM
- native macOS security, installer, signing, privacy, or OS-version behavior: macOS VM
- hardware, recoveryOS, Secure Enclave, unsupported device, performance, or anti-VM behavior: physical Mac
3. Reject any option that cannot repro