glebis/claude-skills

cull-release-verify

Use when verifying or auditing a Cull release, DMG, updater archive, notarization, Homebrew cask, installed version, launch health, or post-publication distribution state.

First seen Jul 15, 2026

Installation

$ npx skills add glebis/claude-skills --skill cull-release-verify

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from glebis/claude-skills · top by installs.

npx skills add glebis/claude-skills

Browse all from glebis/claude-skills

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 372
License MIT
Default branch main
Open issues 6
Status Active

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 1,451 B
  • docs SUMMARY.md 198 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 21 installs

SKILL.md

Cull Release Verify

Principle

Reconstruct release truth from immutable public evidence. Verification is read-only by default.

Verify

  1. Resolve the Cull checkout and select the explicit version or latest public

release.

  1. Run npm run release:cull -- state show --version "$VERSION" --json and parse

exactly one JSON envelope.

  1. Bind the annotated Git tag object and peeled commit to the published release,

authenticated workflow run, provenance, and required asset inventory.

  1. Download artifacts to an isolated temporary directory. Run Cull's exact

artifact verifier; check updater signature, SHA-256 checksums, DMG contents, embedded version and architecture, codesign, Gatekeeper, and notarization staple.

  1. Compare Homebrew version and SHA-256 with public provenance and require its

promotion evidence.

  1. Report version, commit, tag object, workflow, asset hashes, release URL, tap

commit, installed-version evidence, launch evidence, and mismatches.

Default to no installation. When the user explicitly requests an install smoke, use an isolated location and preserve any existing app. Never edit release state, the GitHub release, tags, the tap, system Applications, or cull.db.