Skill Provenance 7.0.0
This release makes the manifest inventory complete. Before 7.0.0, a bundle
containing a file that MANIFEST.yaml did not list still verified with exit 0,
so an added script could pass integrity verification.
Breaking change
validate.sh now fails (exit 1) when anything beneath the bundle root is not
listed in MANIFEST.yaml. Bundles that previously passed with extra files,
including stray .DS_Store files, now fail. List the file in the manifest or
remove it. For a bundle that intentionally shares its directory with other
files, such as a skill at a repository root, --allow-unlisted reports those
entries as warnings and exits 0 without verifying them.
Highlights
- Reports every unlisted file, symlink, or special file as
UNLISTED. Only
the rootMANIFEST.yamlis exempt. - Never follows unlisted symlinks and never reads special files.
- Escapes control characters in reported names so a crafted filename cannot
forge anOKline. - Fails closed on a directory it cannot enumerate.
--updatenever adds unlisted files to the manifest.- Remains zero-dependency and compatible with macOS system Bash 3.2.
- Expands coverage to 43 core plus 21 supplemental evals, 64 total.
Verification
- Signed release commit:
faf6b58c43a403ac62f8516c2b84ba8d36c53e3c - Signed annotated tag:
v7.0.0 skill-provenance.skillSHA-256:
aa8acf27976fb220cd9f3ddb04dfa02da4b44481fa3ff4d4905ebd2e5944a522- Canonical hash validation, complete-inventory regression tests under Bash
5.3 and 3.2, derived package validation, standalone verifier pinning, action
input transport, archive agreement, and search contract passed.
Publisher signatures establish artifact identity, not skill safety. Review the
source, trust boundaries, and changelog before installation.