Conversation
Authenticate local release bundles with the installer's pinned keys, require an expected skill version, and provide JSON audit output without extraction or installation. Prepared with AI assistance from Codex under maintainer direction.
|
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Add success-path coverage for human and JSON output, and correct the misleading invalid-version error message.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
Open (2)
What changed in this PR
Adds an offline impeccable verify-bundle command for authenticating local skill bundles with pinned Ed25519 and SHA-256 verification.
Changes:
- Adds CLI routing, strict version parsing, human-readable and JSON output.
- Returns verified signature metadata.
- Adds documentation, Rust tests, and oracle coverage.
| File | Reviewed change |
|---|---|
tests/oracle/golden/skills-verify-bundle-version-required.json |
Records missing-version output. |
tests/oracle/golden/skills-verify-bundle-namespace-help.json |
Adds namespace help output. |
tests/oracle/golden/skills-verify-bundle-help.json |
Adds command help output. |
tests/oracle/golden/cli-help.json |
Updates root CLI help. |
tests/oracle/DELTAS.md |
Records oracle changes. |
tests/oracle/cases/skills.mjs |
Adds oracle scenarios. |
docs/CLI-CONTRACT.md |
Documents CLI behavior. |
docs/BUNDLE-SIGNING.md |
Documents offline verification. |
crates/skills/tests/verify_bundle_tests.rs |
Adds command regression tests. |
crates/skills/src/verify_bundle.rs |
Implements offline verification and output. |
crates/skills/src/lib.rs |
Registers the verifier module. |
crates/skills/src/commands.rs |
Routes the skills command. |
crates/skills/src/bundle_signature.rs |
Exposes verified envelope metadata. |
crates/detect/src/lib.rs |
Updates root help text. |
crates/cli/src/main.rs |
Adds root CLI dispatch. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| if options.json { | ||
| io.out(&format!( | ||
| "{}\n", | ||
| serde_json::json!({ | ||
| "verified": true, "version": verified.version, "artifact": verified.artifact, | ||
| "keyId": verified.key_id, "size": verified.size, "sha256": verified.sha256, | ||
| }) | ||
| )); | ||
| } else { | ||
| io.out(&format!( | ||
| "Verified {} (skill-v{}).\nSigning key: {}\nSHA-256: {}\nSize: {} bytes\n", | ||
| verified.artifact, verified.version, verified.key_id, verified.sha256, verified.size | ||
| )); |
| bundle_signature::release_version(&format!( | ||
| "https://github.com/pbakaus/impeccable/releases/download/skill-v{version}/universal.zip" | ||
| ))?; |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 825176f. Configure here.
| // Reuse the installer's exact release-version grammar. | ||
| bundle_signature::release_version(&format!( | ||
| "https://github.com/pbakaus/impeccable/releases/download/skill-v{version}/universal.zip" | ||
| ))?; |
There was a problem hiding this comment.
Invalid version error mentions downloads
Low Severity
--version validation reuses release_version, so a bad expected version (for example a leading v) fails with a GitHub redirect message even though verify-bundle never downloads. That reads as a network failure on an offline command.
Reviewed by Cursor Bugbot for commit 825176f. Configure here.




Users reviewing downloaded skill releases currently need a Rust test invocation to verify a bundle without installing it. Add
impeccable verify-bundle universal.zip --version 4.3.1to authenticate local assets offline using the installer's pinned Ed25519 keys and SHA-256 verifier.The expected skill version is required. The command reads
<zip>.sig.jsonby default, supports--signatureand--json, and reports authenticated release metadata. It performs no downloads, extraction, installation, or hook changes. Missing/invalid signatures, unknown keys, altered bytes, and mismatched releases fail closed.Includes CLI help, trust-model and offline verification documentation, regression coverage, and reviewed oracle cases. Generated provider output is intentionally omitted; no release versions are bumped.
Validation:
impeccable-skillstests andcargo test --workspacepass on the isolated branch.cargo build --release -p impeccablepasses.bun run testpasses against the release binary on the isolated branch (core, oracle, detector, live, framework, and plugin E2E).Related: #479.
Prepared with AI assistance from Codex under maintainer direction.