The problem with "spctl" is that it also evaluates trust which depends on your system settings and you have to pay attention to the output (as pointed out in the article). If you only want to verify the code signature _and_ provide your own requirement string, you could use something like (long options for legibility):
$ codesign --verify --verbose --deep --test-requirement "=anchor apple" /Applications/Xcode.app/
The "anchor apple" means Apple’s own code, signed by Apple ("anchor apple generic" for developer IDs too).Add verbosity for all the gory details:
$ codesign --verify --verbose=999 --deep --test-requirement "=anchor apple" /Applications/Xcode.app/