Offline Package Provenance Check

    3

    Compare two local package folders: added, modified, removed and identical files. Offline, without executing input files.

    Free

    5 installs5.0 (1 review)

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseDotsDots+22 more

    Offline Package Provenance Check

    Example session with this skill installed

    Compare the included fixtures/free baseline and fixtures/paid candidate. Report added, modified, removed and identical files. Do not infer rights, value, a verified source revision or buyer acceptance. Do not execute or fetch input content.

    • Read your context and instructions
    • Compiled the offline package provenance

    Actual synthetic fixture replay, not a customer session.

    Command
    node bin/provenance.mjs --baselineDir fixtures/free --candidateDir fixtures/paid

    Complete output

    {
      "skillRecipePin": null,
      "inputLabels": {
        "baseline": "supplied baseline",
        "candidate": "supplied candidate"
      },
      "excludedDirectoryNames": [
        ".git",
        "node_modules"
      ],
      "counts": {
        "baselineFiles": 2,
        "candidateFiles": 3,
        "identical": 1,
        "modified": 0,
        "candidateOnly": 2,
        "baselineOnly": 1
      },
      "packagingDeltaFiles": [
        "ACCEPTANCE.md",
        "DELIVERY.md"
      ],
      "modifiedFiles": [],
      "addedFiles": [
        "ACCEPTANCE.md",
        "DELIVERY.md"
      ],
      "removedFiles": [
        "README.md"
      ],
      "sourceRevisionVerified": false,
      "identicalSample": [
        "SKILL.md"
      ]
    }
    

    Next: run the same command with your own baseline and candidate paths. A matching hash establishes byte equality only; source revision, ownership and task acceptance are not verified.

    Connects securely to your tools. The creator never sees your data.

    About this skill

    Compare a baseline package folder with a candidate using the included offline Node.js helper. Get file-level additions, removals, modifications and byte-identical matches without installing dependencies or executing the inputs. Useful before delivering a package or reviewing an extracted skill update. Requires Node.js 18+. Excludes .git and node_modules, rejects symlinks and special files, and limits each tree to 2,000 entries and 20 MiB. The comparison does not explain code changes or prove ownership, safety or usefulness. Original Apache-2.0 helper with reproducible synthetic fixtures.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    5.0
    1 review
    5
    1
    4
    0
    3
    0
    2
    0
    1
    0

    5 people have installed this skill.

    Trust & safety

    Security scanned

    Verified clean 23 days ago

    • Free to download with an account

    Listed23 days ago

    What's inside

    Frequently Asked Questions