macos-auto-update
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill facilitates the download of the Sparkle framework from its official GitHub repository (
github.com/sparkle-project/Sparkle). This is a well-known and reputable source for macOS software update infrastructure. - [REMOTE_CODE_EXECUTION]: The skill implements remote code execution by design, enabling the application to download and install binary updates from a remote server specified in the
SUFeedURL. Security risks are mitigated by the implementation of EdDSA public-key signatures (SUPublicEDKey) to verify the authenticity of updates before installation. Additionally, the provided code includes#if DEBUGguards to prevent update logic from executing during the development process. - [INDIRECT_PROMPT_INJECTION]: The skill creates an attack surface where the agent processes external data via an
appcast.xmlfeed. - Ingestion points: The application reads an external XML feed from a remote server (e.g., GitHub) as defined in
Info.plist. - Boundary markers: The skill requires the configuration of an
SUPublicEDKeyfor EdDSA signature verification, acting as a cryptographic boundary for trusted content. - Capability inventory: The Sparkle framework has the capability to write files to the application directory and execute updated binaries.
- Sanitization: The framework performs XML schema validation and enforces signature checks on downloaded payloads.
Audit Metadata