Verify Digest

skillerr/verify-digest

sha256:eee30d0110e5
FreeNot anchoredmintedinspectablecapabilitiesdigest-pinnednative

75/ 100 · Solid

WIP · 2.0-signals

Skill Score is actively being developed and will get sharper over time.

  • Sealed package20/20

    Minted .skill blob in the registry

  • Digest published15/15

    sha256 pin published on skillerr.com

  • Permissions declared15/15

    Capabilities / permissions declared

  • Source attested0/10

    No submitter or source URL

  • Transparency log0/15

    Not anchored

  • Release profile15/15

    evaluateReleaseProfile passed

  • Registry signal5/5

    12 install(s) on registry

  • Not revoked5/5

    No revocation on log

Not a malware scan. Not “safe to run.” Transparent registry signals only. Inclusion is not endorsement.

npx @skillerr/add skillerr/verify-digest

Registry pin: sha256:eee30d0110e5 (shown on TrustView; install by name resolves to this sealed blob)

Sealed install targets

Writes verify-digest.skill (sealed ZIP) plus optional skillerr.json. Not a bare SKILL.md.

Download verify-digest.skill

Sealed ZIP with digest + skillerr.json. Not a bare SKILL.md.

Free skills install with npx @skillerr/add. Sign in for account history.

Install and download deliver a digest-pinned open .skill package (docs.skillerr.com). Pasting a SKILL.md from the internet has none of this proof.

  • verify-digest.skill ZIP

    Open-protocol .skill ZIP (skill.json + workflow), not a public raw SKILL.md URL

  • Registry digest pin

    sha256:eee30d0110e5…

  • Inspect before run

    TrustView on skillerr.com; SKILL.md is a lossy adapter inside the package

  • Permissions surface

    Capabilities declared for review before install

  • Transparency log

    Inclusion proof in the skillerr.com registry log

  • netNetworkelevated

    Call remote APIs or fetch URLs

Declarations for humans and agents. Not a runtime sandbox guarantee.

Confirm the digest on this page matches the live registry. This checks identity pins only: not a security scan.

expect sha256:eee30d0110e53f76
npx @skillerr/add info skillerr/verify-digest
curl -sS https://skillerr.com/api/v1/skills/skillerr/verify-digest | grep -o '"digest":"[^"]*"'

Check a sealed .skill digest against the registry pin and log proof.

Agent meta-skill for verifying package digests on skillerr.com: compare local sha256 to the catalog pin, fetch inclusion proof when available, and report VerifyResult reasons without claiming malware safety.

TrustView preview on skillerr.com. Install and download serve the sealed package: there is no public raw SKILL.md URL.

---
name: verify-digest
title: Verify Digest
description: Check a sealed .skill digest against the registry pin and log proof.
---

# Verify Digest

Agent meta-skill for verifying package digests on skillerr.com: compare local sha256 to the catalog pin, fetch inclusion proof when available, and report VerifyResult reasons without claiming malware safety.
Public Ledger
Not anchored
published_at
2026-07-20T18:00:00.000Z
version
0.1.0
updated_at
2026-07-20T18:00:00.000Z
license
MIT
minted_at
2026-07-20T18:27:53.023Z
permanence
in registry log
digest
sha256:eee30d0110e53f76183da091efc11438937e10f591bd05050a91569afe4a6032

Public permanence uses Sigstore Rekor. The ledger link is shown when a real logIndex was recorded at mint. Green Anchored requires an offline inclusion proof verify. Catalog claims alone never paint Anchored. Inclusion is not endorsement.