Run a standard security sweep (especially if the file was received via external transfer).

Verify the SHA-256 or MD5 hash against the source manifest.

While specific contents vary by build, this package typically includes: