Verification matrix
Match Expo verification to the requested risk surface.
| Surface | Local check | Remaining risk |
|---|---|---|
| Skills and catalog | generator check, verify-skills | host-specific activation |
| Foundation invariants | invariant validator and unit tests | unmodeled natural-language contradictions outside configured files |
| Vendored Expo snapshots | manifest provenance validation | unverified snapshots have no recorded upstream revision/date |
| Installer | conflict and uninstall tests | user home permissions |
| Consumer app audit | repository evidence plus safe local $expo-verify checks |
device, native, cloud, and skipped-check risk |
| Design review | source inspection plus screenshots/runtime when available | visual, Dynamic Type, screen-reader, reduced-motion, and device gaps |
| Expo JavaScript | TypeScript, Expo Doctor | native runtime behavior |
| Web routes | expo export --platform web |
device-only controls |
| Native module | development client or device | unavailable without native runtime |
| EAS service | explicit authorized command | cost, credentials, remote state |