A scan report is only worth what you trust about who produced it. Dual-side verification removes that question: the publisher scans the skill before sharing it, your client re-scans the archive it actually received, and the server compares the two reports against a SHA-256 tree hash of the bytes. Matching reports return verified; a mismatch returns divergent or critical and tells you which files disagree.

That makes tampering between publish and install detectable rather than a matter of trust — including tampering by the registry itself. The posts below cover the mechanics, the threat model it does and does not cover, and how the verdicts appear on a skill page.

16 articles in this guide