mcpbeat

Cull Release Verify

glebis/cull-release-verify

Use when verifying or auditing a Cull release, DMG, updater archive, notarization, Homebrew cask, installed version, launch health, or post-publication distribution state.

426 tokens
context cost
the whole folder, loaded on every use
2
files
instructions only
0
copies elsewhere
how many repositories repackaged it
337
stars on the repo
on the repository, not the skill itself

Install

one command, takes just this skill from the repository
npx skills add https://github.com/glebis/claude-skills --skill cull-release-verify

What comes with it

254 bytes besides the instruction
agents/openai.yaml

The instruction itself

3 sections, as written by the author

Cull Release Verify

Principle

Reconstruct release truth from immutable public evidence. Verification is

read-only by default.

Verify

  • Resolve the Cull checkout and select the explicit version or latest public

release.

  • Run npm run release:cull -- state show --version "$VERSION" --json and parse

exactly one JSON envelope.

  • Bind the annotated Git tag object and peeled commit to the published release,

authenticated workflow run, provenance, and required asset inventory.

  • Download artifacts to an isolated temporary directory. Run Cull's exact

artifact verifier; check updater signature, SHA-256 checksums, DMG contents,

embedded version and architecture, codesign, Gatekeeper, and notarization

staple.

  • Compare Homebrew version and SHA-256 with public provenance and require its

promotion evidence.

  • Report version, commit, tag object, workflow, asset hashes, release URL, tap

commit, installed-version evidence, launch evidence, and mismatches.

Default to no installation. When the user explicitly requests an install smoke,

use an isolated location and preserve any existing app. Never edit release state,

the GitHub release, tags, the tap, system Applications, or cull.db.

How to use it

Copy the folder

Take glebis/cull-release-verify from the repository into ~/.claude/skills for personal use, or into .claude/skills inside a project.

Check the name does not clash

The agent identifies a skill by the name field in its header. Two skills with the same name cannot sit side by side — one of them will be ignored.