# chainctl skills verify

URL: https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/platform/chainctl/chainctl-docs/chainctl_skills_verify.md
Last Modified: October 8, 2026
Tags: chainctl, Reference, Product

 chainctl skills verify Verify that Chainguard signed a published skill.
Synopsis Verify that Chainguard&rsquo;s publishing pipeline signed a published skill for the organization that owns it.
The reference accepts org/name:tag or org/name@sha256:DIGEST. A tag is resolved once and the digest is verified; the output prints that digest so you can pin it.
Verification passes only when a sigstore bundle attached to the digest chains to the public-good Sigstore trusted root, was issued by https://issuer.enforce.dev to exactly the owning organization&rsquo;s SKILLS service principal, and has a verified transparency-log entry and timestamp. The signing identity of Chainguard&rsquo;s own organizations (public, chainguard) is built into chainctl; for any other organization, chainctl reads its SKILLS binding with your credentials, which requires the viewer role (or higher) on that organization.
The result is one of: verified, unsigned, failed, or skipped. Skills on a staging or development registry are skipped with a warning; uploads are never Chainguard-signed and always fail. The command exits 0 for verified and skipped, and 1 for unsigned and failed (the status field tells them apart); an error that stops verification from running also exits nonzero.
chainctl skills verify &lt;ref&gt; [flags] Examples # Verify the latest version of a skill: chainctl skills verify chainguard/github/lint # Verify a pinned digest and print the result as JSON: chainctl skills verify chainguard/github/lint@sha256:&lt;digest&gt; -o json Options inherited from parent commands --api string The url of the Chainguard platform API. (default &#34;https://console-api.enforce.dev&#34;) --audience string The Chainguard token audience to request. (default &#34;https://console-api.enforce.dev&#34;) --config string A specific chainctl config file. Uses CHAINCTL_CONFIG environment variable if a file is not passed explicitly. --console string The url of the Chainguard platform Console. (default &#34;https://console.chainguard.dev&#34;) --force-color Force color output even when stdout is not a TTY. -h, --help Help for chainctl --issuer string The url of the Chainguard STS endpoint. (default &#34;https://issuer.enforce.dev&#34;) --log-level string Set the log level (debug, info) (default &#34;ERROR&#34;) -o, --output string Output format. One of: [csv, env, go-template, id, json, markdown, none, table, terse, tree, wide] -v, --v int Set the log verbosity level. SEE ALSO chainctl skills	- Skills registry related commands. 
