# store-ready: Gate 1, static package audit

Read by `/multi-agent:store-ready` for Step 4.

## iOS

`ios_app_store_audit({archive_path, rules: "all"})`. Consult the
`apple-archive-compliance` skill for what each rule means.

Needs `@mmerterden/multi-agent-toolkit-mcp` ≥ v3.0.0, which provides the tool. When the
MCP server is not registered, the same 18 rules run directly from the package:

```bash
node -e "import('@mmerterden/multi-agent-toolkit-mcp/tools/ios-app-store-audit/index.js').then(m => m.runAudit({ archivePath: '<path>', rules: 'all' }).then(r => console.log(JSON.stringify(r))))"
```

Use the fallback only when the tool is genuinely absent, and say in the report
which path ran  -  a rule set that silently differed between two invocations is
worse than a missing gate.

Then, whichever path ran, count `<archive>/dSYMs/*.dSYM`. Zero is a blocking
finding: `[SYMBOLS] archive carries no dSYM; crash reports will not symbolicate`,
with the hint `DEBUG_INFORMATION_FORMAT = dwarf-with-dsym` for the Release
configuration. This check runs from the package alone and does not need the
MCP tool.

## Android

`android_apk_audit` on the artifact, plus the `google-play-compliance` skill's 21
rules  -  `bundletool validate` and manifest dump, `aapt2 dump badging`,
`apksigner verify`, ABI / native scan.

Then, when the module has `minifyEnabled true` and the bundle build produced no
`mapping.txt`, raise the same class of blocking finding:
`[SYMBOLS] minified bundle carries no mapping.txt; crash reports will not
deobfuscate`. This check reads the module config and the build output alone
and does not need the MCP tool.
