Skip to main content
Use this script to remove Stable () through Jamf Pro, Iru, or Fleet. Download the uninstall script or copy it below unchanged. It calls the uninstaller bundled with the installed Silmaril app.

Remove through MDM

1

Pause installation

Pause every Silmaril app installation assignment or policy for the target Macs, so the vendor cannot reinstall Silmaril. Leave unrelated management enabled.Do not delete a shared Blueprint, fleet, or group. Removing a tag, group, or label does not uninstall Silmaril.Expected result
Jamf, Iru, or Fleet can no longer reinstall Silmaril onto the target Macs. Unrelated management stays enabled. Vendor-specific task placement is in the Jamf, Iru, and Fleet uninstall steps.
If this differs
Leave the uninstall script unrun until those install policies are paused. Otherwise MDM can put the app back.
2

Prepare the user session

Have the affected user sign in and save their work. The uninstaller removes that user’s Silmaril integrations and local data, removes the shared application, and may stop and reopen agent applications. On shared Macs, arrange cleanup for every affected account before removing the app.Expected result
The affected user is signed in at the console. Console UID is above 500.
If this differs
The script exits 69 and attempts no removal when it cannot identify a signed-in user, or when that UID is 500 or below. Sign the user in and run the script again.
3

Run through MDM

Copy the script below unchanged into a root script task in Jamf Pro, Iru, or Fleet, or upload the downloaded file. Keep the JSON receipt and the exit code from the task.Expected result
The task runs as root and returns the uninstaller JSON plus exit code 0 or 2, or another code explained below.
If this differs
Exit 77 means the script was not run as root. Exit 69 before the uninstaller runs means there is no eligible signed-in user, or the bundled uninstaller at /Applications/Silmaril.app/Contents/Helpers/SilmarilUninstaller is unavailable. Review the installed app and any previous receipt. A missing app or helper does not prove that earlier cleanup completed.
4

Complete the reported follow-up

Use the exit-code table below to review the result. Remove only the Silmaril configuration profile through MDM when policy should no longer apply. Confirm baseline assignments and controls are still intact. Local credential removal does not revoke the server API key.Expected result
Exit 0, with the app removed, and only the Silmaril profile removed through MDM when policy should stop applying. Baseline assignments and controls remain.
If this differs
Follow the row for that exit code. Profile removal is a separate MDM change. Removing the profile does not uninstall Silmaril, and uninstalling the app does not remove the profile.

Managed uninstall script

Exit codes

For Stable (), Guardian Disabled, a receipt can report successful app and integration removal with only Managed permissions and Notification permission remaining. Managed permissions means MDM policy may remain. Notification permission may be unverified. Remove only the Silmaril profile through MDM and, if Silmaril still appears in System Settings > Notifications, turn off Allow Notifications. Confirm baseline assignments and controls remain intact. These permission entries alone do not indicate remaining protection. If the receipt reports remaining Guardian components, failed app removal, or protectionMayStillRun=true, do not continue until that reported item is resolved. After the app is removed, complete permission follow-up directly through MDM or System Settings. Do not rerun a missing helper to obtain exit 0. Contact support before replacing an incompatible installed variant.
Exit 2 is a receipt to read, not a Guardian finding. Confirm installed state separately. Check /Applications/Silmaril.app and its process, the Guardian daemon dev.silmaril.guardian, and the system extension dev.silmaril.SilmarilMacOS.GuardianExtension.