Archive verification
Verification should stand on its own.
An offline command-line verifier is available in the private project. Web uploads remain unavailable. No package is executed, trusted merely because it includes a public key, or described as permanent.
An archive verifier must check file bounds, safe paths, payload and metadata hashes, canonical manifests, and signature mathematics. Trusted origin requires a key obtained independently of the package.
Until the archive release workflow and verifier pass their acceptance tests, archive publication and uploads remain unavailable.