macos-auto-update

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the download of the Sparkle framework from its official GitHub repository (github.com/sparkle-project/Sparkle). This is a well-known and reputable source for macOS software update infrastructure.
  • [REMOTE_CODE_EXECUTION]: The skill implements remote code execution by design, enabling the application to download and install binary updates from a remote server specified in the SUFeedURL. Security risks are mitigated by the implementation of EdDSA public-key signatures (SUPublicEDKey) to verify the authenticity of updates before installation. Additionally, the provided code includes #if DEBUG guards to prevent update logic from executing during the development process.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates an attack surface where the agent processes external data via an appcast.xml feed.
  • Ingestion points: The application reads an external XML feed from a remote server (e.g., GitHub) as defined in Info.plist.
  • Boundary markers: The skill requires the configuration of an SUPublicEDKey for EdDSA signature verification, acting as a cryptographic boundary for trusted content.
  • Capability inventory: The Sparkle framework has the capability to write files to the application directory and execute updated binaries.
  • Sanitization: The framework performs XML schema validation and enforces signature checks on downloaded payloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — macos-auto-update