asset-pipeline
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- Remote Resource Ingestion: The skill describes a mechanism for updating VM assets (kernel, initrd, rootfs) by fetching a manifest from a user-provided URL (
capsem update --assets --manifest <URL>). While this is a standard update pattern for the tool, it involves downloading external data that is subsequently used to provision virtual environments. - Build-Time Verification Reliability: The system uses
build.rsto extract and embed asset hashes at compile time for boot-time verification. The documentation notes a potential consideration where verification may be silently skipped if the manifest is missing or malformed during the build process, which could result in assets booting without BLAKE3 integrity checks. - Command Execution via Task Runner: The skill utilizes
justrecipes to orchestrate asset builds, signing, and VM deployments. These recipes interact with local Docker and Colima environments to perform complex operations like initrd repacking and rootfs generation. - Indirect Prompt Injection Surface: The tool processes external JSON manifests which determine the versions and locations of binary assets. Although the skill emphasizes BLAKE3 verification, the ingestion of manifests from arbitrary URLs represents a supply chain vector that is mitigated by the described attestation and checksum verification contracts.
Audit Metadata