macos-release

Fail

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user or agent to fetch code from a remote, untrusted third-party repository not associated with the skill's author. Specifically, it recommends executing go run github.com/fayazara/macos-app-skills/release/cli@latest to automate the release process.
  • [REMOTE_CODE_EXECUTION]: The skill facilitates remote code execution by encouraging the use of go run on a remote repository URL. This allows externally hosted code to be compiled and executed directly on the user's machine without prior inspection of the source code.
  • [COMMAND_EXECUTION]: The provided Go CLI tool and the manual guide perform numerous system commands to manage the release pipeline, including:
  • create-dmg: For packaging the application.
  • gh release create: For interacting with GitHub Releases.
  • git push/commit/add: For version control and appcast updates.
  • plutil: For extracting values from macOS property list files.
  • sign_update: A Sparkle binary found within the user's DerivedData directory used for EdDSA signing.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an indirect injection surface as it ingests untrusted data from multiple sources to build release metadata.
  • Ingestion points: Reads project configuration from release.json, app versions and build numbers from Info.plist, existing update history from appcast.xml, and release notes from stdin.
  • Boundary markers: The CLI includes a summary display and an interactive confirmation prompt confirm("Proceed with release?", true) before performing sensitive operations like pushing code or creating releases.
  • Capability inventory: Uses exec.Command to invoke git, gh, and create-dmg (SKILL.md and cli/main.go).
  • Sanitization: Employs xmlEscapeText and xmlEscapeAttr to sanitize data inserted into the XML appcast, and utilizes Go's exec.Command which prevents shell-level command injection by treating arguments as a discrete array.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — macos-release