There's no easy way. Even if you do verify it, there's no guarantee Apple won't push an update with a backdoor because NSA asked them to.
That's why it's better to use Crypto.Cat - its source is the executable. Verifying the hash is enough to make sure the source code didn't change.