Agent skill

Verify

by electron in electron/osx-sign

Build-and-drive recipe for verifying @electron/osx-sign changes end-to-end on macOS.

BSD-2-ClauseAuto-check: notes

Install Verify

skills CLI
$ npx skills add electron/osx-sign --skill verify -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install electron/osx-sign verify --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/electron/osx-sign.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/verify .claude/skills/verify && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
verify
GitHub stars
632
Token cost
~562 tokens
SKILL.md length
193 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
BSD-2-Clause

At a glance

Build-and-drive recipe for verifying @electron/osx-sign changes end-to-end on macOS.

  • SKILL.md covers Build, Surfaces, Getting a real app to package and Observing the output pkg, plus 1 more section
  • Calls node and yarn

What it does

Verify is an agent skill from electron/osx-sign. Build-and-drive recipe for verifying @electron/osx-sign changes end-to-end on macOS.

Its SKILL.md is about 560 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with macOS and Electron. The repository describes itself as: Codesign Electron macOS apps. The licence is BSD-2-Clause.

Example prompts

  • “/verify”

What it can do on your machine

Read from SKILL.md and the folder at commit 222d790. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • node
    • yarn

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use yarn, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Verify loads about 562 tokens when it runs. Until then it costs about 23 tokens; SKILL.md has 193 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~23
When it runs · the whole SKILL.md, loaded when a task matches
~562

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:39
    - Actually installing requires sudo — don't.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from electron/osx-sign at commit 222d790, republished under its BSD-2-Clause licence (© electron). 193 words, ~562 tokens.

Download SKILL.mdSave it as .claude/skills/verify/SKILL.md (or your agent's skills folder).
name
verify
description
Build-and-drive recipe for verifying @electron/osx-sign changes end-to-end on macOS.

Verifying @electron/osx-sign

Build

bash
yarn build        # tsc → dist/ (the bin/ CLIs import from dist/)

Surfaces

  • CLI: node bin/electron-osx-flat.mjs <App.app> [--implementation=js] [--platform=darwin|mas] [--pkg=out.pkg] and node bin/electron-osx-sign.mjs <App.app> [...]. Both read from dist/, so build first.
  • Library: flat() / sign() from the package root export.

Getting a real app to package

Download a real Electron.app (cached by @electron/get after first run):

bash
node -e '
const { downloadArtifact } = require("@electron/get");
const { extract } = require("@electron-internal/extract-zip");
downloadArtifact({ version: "35.0.3", platform: "darwin", arch: process.arch, artifactName: "electron" })
  .then((zip) => extract(zip, { dir: process.argv[1] }))' /tmp/electron-dist

Observing the output pkg

  • pkgutil --expand-full out.pkg expanded-dir then diff -r App.app expanded-dir/*.pkg/Payload/App.app is the strongest check — it runs Apple's real extraction path. "Directory loop detected" warnings from diff on framework symlinks are benign when they appear on both sides.
  • lsbom <extracted Bom> validates the Bill-of-Materials.
  • installer -pkg out.pkg -volinfo exercises Installer's package parsing without installing.
  • Actually installing requires sudo — don't.

Gotchas

  • Native Apple tools (pkgbuild/productbuild/pkgutil/installer/lsbom) hang or crash under the Bash-tool seatbelt sandbox. Run them with the sandbox disabled.
  • Files created by this session's processes get com.apple.provenance xattrs, which make native pkgbuild emit AppleDouble (._*) entries. When byte-comparing against native output, filter ._* entries and renumber cpio inodes (see spec/pkg-utils/helpers.ts normalizeCpio).
  • Signing verification needs the self-signed identity from spec/ci/generate-identity.sh; without it, sign.spec.ts fails with "No identity found" (pre-existing on dev machines).
  • yarn bench benchmarks the JS packager against the native tools; OSX_SIGN_BENCH_APP=path points it at an existing .app.

© electron, BSD-2-Clause. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/verify of electron/osx-sign.

Open the folder on GitHubat commit 222d790

Compare with similar skills

Verify next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Verify compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Verify this skillelectron/osx-sign632—~562Automated safety check: NotesBSD-2-Clause
Desktop ElectronOpenHands/OpenHands90k—~302Automated safety check: PassMIT
Tinyjstarwin/tinyjsapp671—~2.9kAutomated safety check: PassMIT
App Store Deployromankurnovskii/BrewMate301—~813Automated safety check: NotesMIT
Interceptor macOSHacker-Valley-Media/Interceptor514—~2kAutomated safety check: PassCustom licence
Electron App Source ExtractorJimLiu/baoyu-skills26k1 repos~2.6kAutomated safety check: PassMIT

Similar skills

  • Desktop Electron

    OpenHands/OpenHands

    This skill should be used when the user asks to "change the desktop app", "package Electron", "build a universal macOS app", "bundle Node or uv", "fix Electron startup", or changes electron/…

    90k GitHub stars~302 tokensUpdated today
    Auto-check passed
  • Tinyjs

    tarwin/tinyjsapp

    Build and modify tinyjs desktop apps — tiny macOS (and beta Windows/Linux) apps with a txiki.js JavaScript backend and a native webview window.

    671 GitHub stars~2.9k tokensUpdated yesterday
    Auto-check passed
  • App Store Deploy

    romankurnovskii/BrewMate

    Automates the build and deployment of the Electron app to the Mac App Store and TestFlight.

    301 GitHub stars~813 tokensUpdated 9 days ago
    MobileAuto-check: notes
  • Interceptor macOS

    Hacker-Valley-Media/Interceptor

    Drive native macOS apps via interceptor macos : AX trees, background click/type/keys/drag/scroll, occluded or minimized window capture, browser chrome, URL bars, OS dialogs, Apple Events, trusted OS…

    514 GitHub stars~2k tokensUpdated 4 days ago
    Productivity & AutomationAuto-check passed
  • Unpacks an installed Electron app's asar bundle and restores readable source from its JavaScript source maps when one is available.

    26k GitHub starsUsed in 1 repo~2.6k tokens
    DevelopmentAuto-check passed
  • 构建并验证 DeepWrite Windows、macOS 测试安装包,排查打包错误、修复后继续。用于打包、测试包、Win/Mac 包及相关流程修改;版本递增和发布另用 package-patch-release。

    559 GitHub stars~574 tokensUpdated 3 days ago
    Auto-check passed

Works with

Questions about Verify

What does Verify do?

Build-and-drive recipe for verifying @electron/osx-sign changes end-to-end on macOS. Verify is an agent skill from electron/osx-sign. Build-and-drive recipe for verifying @electron/osx-sign changes end-to-end on macOS.

How do I install Verify in Claude Code?

Run `npx skills add electron/osx-sign --skill verify -a claude-code`. Or copy the skill folder (.claude/skills/verify in electron/osx-sign) into .claude/skills/verify in your project. Claude Code loads it when a task matches its description.

How do I install Verify in Codex?

Run `npx skills add electron/osx-sign --skill verify -a codex`. Or copy the skill folder (.claude/skills/verify in electron/osx-sign) into .agents/skills/verify in your project. Codex loads it when a task matches its description.

Can I use Verify in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add electron/osx-sign --skill verify -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/verify, .gemini/skills/verify, .github/skills/verify and .opencode/skills/verify in your project.

What does Verify need to run?

Going by SKILL.md and its folder, Verify needs the command-line tools its instructions call (node and yarn).

Does Verify access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Verify safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Verify use?

Verify is published under the BSD-2-Clause licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Verify use?

About 562 tokens (SKILL.md is roughly 2.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Verify?

Skills that share tags, products or a category with Verify: Desktop Electron (OpenHands/OpenHands, 90k stars), Tinyjs (tarwin/tinyjsapp, 671 stars), App Store Deploy (romankurnovskii/BrewMate, 301 stars) and Interceptor macOS (Hacker-Valley-Media/Interceptor, 514 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Verify?

electron (a GitHub organization) maintains it in electron/osx-sign, which has 632 GitHub stars. The repository was last updated on October 6, 2026.

Source: electron/osx-sign on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.