catchlaw-offline-guaranteelisted
Install: claude install-skill zakariaf/CatchLaw
# Catchlaw Offline Guarantee
"100% offline" is printed on the store listing and said to a regulator, so it is held up by the
compiler and the operating system, never by discipline. This skill owns the four layers that make
the claim VERIFIABLE — the undeclared dependency, the stripped Android permission, the honest iOS
gap, and the `dart:io` guard test — plus the banned-package list and the packet-capture ritual. It
does not own durability, migrations or failure typing.
Read the reference for the task at hand:
- `references/four-layers.md` — layer strength ladder, banned package table, manifest snippets and
merger rules, the iOS gap, the `dart:io` split, transitive allowlist, API grep list.
- `references/verification-ritual.md` — why proxies lie, PCAPdroid, adb tcpdump, rvictl plus
Wireshark, pass criteria, release checklist, evidence retention, failure triage.
Run `scripts/check_no_network.sh` before a PR.
Durability, DAOs and transactions belong to `persistence-drift`; forward-only schema changes to
`run-migration`; `Result` and failure types to `error-handling-typed-results`. This skill only ever
asserts that no code path can reach a socket, and that the asset databases are the whole world.
## Non-negotiable rules
1. **The networking package is never declared, at any depth.** `pubspec.yaml` carries no `http`,
`dio`, `web_socket_channel`, `grpc`, `firebase_core`, `connectivity_plus`, `url_launcher`,
`googleapis` or `google_fonts` — not in `dependencies`, not