homebrew-cask-authoring
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to perform standard development tasks using CLI tools including
brewfor cask management,gitandghfor version control and pull request submission,lipofor inspecting binary architectures, andshasumfor checksum calculation. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data to generate cask definitions, creating an attack surface for indirect prompt injection.
- Ingestion points: The agent reads application metadata from
Info.plistfiles, binary headers vialipo, and external search results from GitHub pull requests. - Boundary markers: No explicit delimiters or instructions to ignore embedded content are specified for the ingested data.
- Capability inventory: The skill utilizes shell command execution, file writing for cask files, and network operations through the
ghCLI. - Sanitization: The skill relies on a mandatory human verification step, as outlined in the 'AI Disclosure' section, to validate generated cask content and zap paths.
- [EXTERNAL_DOWNLOADS]: The skill references official Homebrew documentation at
docs.brew.shand manages contributions through the well-knownHomebrew/homebrew-caskGitHub repository.
Audit Metadata