Compare dotenv files and report which keys are missing or extra, by name only.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts — it cannot prove the absence of malicious code.
Compare dotenv files and report which keys are missing or extra, by name only.