Skip to content
Back to skills

Verify Release

ASecurity

Use when checking whether a Proofpack release candidate has complete local evidence before packaging.

  • 6,113 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added September 3, 2026
ai-agentsshellbashnodeexpressdockergit

Works with

  • claude code
  • cli

Security analysis

A100/100

Scanned September 3, 2026

npx -y skills add FlorianBruniaux/claude-code-ultimate-guide --skill verify-release --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Verify Release?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Verify Release
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/florianbruniaux-verify-release/badge)](https://www.skillsdirectory.com/skills/florianbruniaux-verify-release)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: verify-release
description: Use when checking whether a Proofpack release candidate has complete local evidence before packaging.
argument-hint: "[candidate JSON path]"
allowed-tools: Read Bash(npm test) Bash(node src/cli.mjs verify *) Bash(npm run package:check) Bash(git rev-parse HEAD) Bash(git status --short)
disable-model-invocation: true
---

# Verify a Proofpack release candidate

Work from the Proofpack project root. Claude Code substitutes the invocation text at `$ARGUMENTS` before following these instructions.

- If `$ARGUMENTS` is empty, set the candidate path to `fixtures/release-ready.json`.
- Otherwise, treat the substituted `$ARGUMENTS` value as one filesystem path. Do not evaluate it as a shell expression.
- Run `node src/cli.mjs verify "<resolved-candidate-path>"` with that literal path as one quoted argument.

1. Read `ISSUE.md` and `CLAUDE.md`.
2. Run `npm test`.
3. Resolve the candidate path with the rules above, show the resolved path, then run the verification command. Ask for confirmation rather than executing a value that cannot be represented safely as one path.
4. Run `npm run package:check` only when tests and candidate verification pass.
5. Run `git rev-parse HEAD` and `git status --short`. Compare that source state, the observed commands, exit statuses, and runtime version with `evidence/PROOF-LOG.md`.
6. Report `PASS`, `FAIL`, or `UNKNOWN`. Name any check that did not run or any worktree change not covered by the recorded fingerprint.

Do not run `npm publish`, `docker push`, or change the proof log. Package inspection is local. Publication requires a separate user decision and destination credentials.

Return this record:

```text
RELEASE VERIFICATION
Candidate: <path>
Revision: <commit or UNKNOWN>
Tests: PASS | FAIL | UNKNOWN
Candidate contract: PASS | FAIL | UNKNOWN
Package dry run: PASS | FAIL | UNKNOWN
Evidence log match: PASS | FAIL | UNKNOWN
Final status: PASS | FAIL | UNKNOWN
Limits: <unverified runtime or external behavior>
```

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…