homebrew-cask-authoring

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to perform standard development tasks using CLI tools including brew for cask management, git and gh for version control and pull request submission, lipo for inspecting binary architectures, and shasum for checksum calculation.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data to generate cask definitions, creating an attack surface for indirect prompt injection.
  • Ingestion points: The agent reads application metadata from Info.plist files, binary headers via lipo, and external search results from GitHub pull requests.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded content are specified for the ingested data.
  • Capability inventory: The skill utilizes shell command execution, file writing for cask files, and network operations through the gh CLI.
  • Sanitization: The skill relies on a mandatory human verification step, as outlined in the 'AI Disclosure' section, to validate generated cask content and zap paths.
  • [EXTERNAL_DOWNLOADS]: The skill references official Homebrew documentation at docs.brew.sh and manages contributions through the well-known Homebrew/homebrew-cask GitHub repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 10:06 AM
Security Audit — agent-trust-hub — homebrew-cask-authoring