sn-update
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONPERSISTENCE
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill downloads and installs executable skill definitions into the agent's environment.
- It clones remote content and copies it directly into the agent's active skill directories (
~/.openclaw/skills/or~/.hermes/skills/). - These installed files are subsequently loaded and executed by the agent in future sessions.
- [COMMAND_EXECUTION]: The skill uses shell commands for repository and file system management.
- It executes
gitcommands (clone, fetch, log, describe) to manage version control and synchronization of the skill bundle. - It performs directory operations including moving, copying, and deleting files within the user's home directory.
- [EXTERNAL_DOWNLOADS]: Fetches updates from a remote Git repository.
- The default source is the vendor's repository at
github.com/OpenSenseNova/SenseNova-Skills.git. - The skill instructions explicitly allow for user-provided URL overrides (forks), which introduces a potential vector for installing untrusted code.
- [INDIRECT_PROMPT_INJECTION]: The skill acts as a gateway for external content to influence agent behavior.
- Ingestion points: External Markdown and script files from the remote repository.
- Boundary markers: None identified; the skill content is integrated directly into the agent's execution path.
- Capability inventory: Network access (git), file system write/delete access, and the ability to modify the agent's own logic (self-updating).
- Sanitization: There is no evidence of integrity checking (e.g., GPG signatures) or content sanitization for the downloaded files beyond Git SHA comparisons.
- [PERSISTENCE]: Modifies the agent's permanent installation to maintain functionality across restarts.
- By installing and updating files in the agent's core skill directories, the skill achieves persistence for the new or modified code.
Audit Metadata