The App Store version
What Apple's App Sandbox changes for MacScout, from file access to commands and copied apps.
MacScout from the Mac App Store runs in Apple's App Sandbox, like every app from the store. The sandbox limits what an app can reach on your Mac, and for a file manager that shows in a few places.
Access to your files
On first launch, MacScout shows Allow access to your files. Click Allow Access…, then Allow Access in the window that opens, and MacScout can browse your startup disk. You can also choose a single folder there instead.
- The config file is in your home folder, so custom actions need access to it.
- Other drives may need their own access. When a folder on another drive doesn't open, click Allow Access… in its place.
- Settings → General → Folder Access lists what MacScout can open, and lets you add or remove folders.
Commands for the terminal
The sandbox doesn't let MacScout start a command in another app. So package scripts, make targets, Claude Code Here, Codex Here and actions with "output": "terminal" open your terminal in the folder and put the command on the clipboard. Paste it with ⌘V and press Return.
Git's Status and Log show their output in a window instead.
Developer tools
Commands from custom actions run inside the sandbox too, and the sandbox decides which programs they can start. Programs that come with macOS work, like zip, rsync, sips, perl and ruby, and so do the ones inside Xcode, the Command Line Tools and the apps in your Applications folder.
Programs you installed anywhere else don't start: tools from Homebrew, nvm, npm or pip, and installers that put their tools in /usr/local. They stop with operation not permitted. A script of your own runs when a shell reads it, like zsh ~/bin/tidy.sh, but not when you start it as ~/bin/tidy.sh, and the programs it starts follow the same rules.
Some tools in /usr/bin only start the matching tool from Xcode or the Command Line Tools, and that step doesn't work in the sandbox: git, make, python3, clang, swift and opendiff, among others. They stop with this message:
xcrun: error: cannot be used within an App Sandbox.Give those tools their full path, like /Applications/Xcode.app/Contents/Developer/usr/bin/git. For everything else, give the action "output": "terminal": you paste the command into your terminal, where it runs outside the sandbox. The Git menu finds a git that works on its own.
Files MacScout creates
macOS marks every file that an app from the store creates or copies, the way it marks downloads. Documents open as usual. Apps, scripts and command-line tools that MacScout copied go through Gatekeeper the first time you open them, and macOS may refuse to run the ones that aren't signed. Copy those with Finder. MacScout can't remove the mark.
Locked Files
Show Apps Using This… needs lsof, which can't run in the sandbox, so the App Store version leaves it out. Lock and Unlock work as usual.