Preserve a strict read-only boundary
Preserve a strict read-only boundary.
Read-only Codex and Claude Code skill for verifying GitHub releases, npm packages, tags, CI, install commands, and catalog metadata.
A release can look complete in one system while its tag, package version, CI, install instructions, or catalog entry points elsewhere.
Auditing must never mutate or repair release state.
Authentication/network errors cannot be interpreted as artifact absence.
Mutable aliases such as latest are weaker proof than package@version.
Evidence collection from Git/GitHub/npm/catalog; deterministic identity comparison and classification; human-facing pass/warning/fail/blocked report.
Evidence collection from Git/GitHub/npm/catalog.
Deterministic identity comparison and classification.
Human-facing pass/warning/fail/blocked report.
Preserve a strict read-only boundary.
Normalize findings into four explicit states instead of a vague success flag.
Prefer immutable version evidence and treat correct mutable aliases as conditional.
Share your challenge, scope, and timeline to start a focused conversation.