sn-update

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONPERSISTENCE
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill downloads and installs executable skill definitions into the agent's environment.
  • It clones remote content and copies it directly into the agent's active skill directories (~/.openclaw/skills/ or ~/.hermes/skills/).
  • These installed files are subsequently loaded and executed by the agent in future sessions.
  • [COMMAND_EXECUTION]: The skill uses shell commands for repository and file system management.
  • It executes git commands (clone, fetch, log, describe) to manage version control and synchronization of the skill bundle.
  • It performs directory operations including moving, copying, and deleting files within the user's home directory.
  • [EXTERNAL_DOWNLOADS]: Fetches updates from a remote Git repository.
  • The default source is the vendor's repository at github.com/OpenSenseNova/SenseNova-Skills.git.
  • The skill instructions explicitly allow for user-provided URL overrides (forks), which introduces a potential vector for installing untrusted code.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a gateway for external content to influence agent behavior.
  • Ingestion points: External Markdown and script files from the remote repository.
  • Boundary markers: None identified; the skill content is integrated directly into the agent's execution path.
  • Capability inventory: Network access (git), file system write/delete access, and the ability to modify the agent's own logic (self-updating).
  • Sanitization: There is no evidence of integrity checking (e.g., GPG signatures) or content sanitization for the downloaded files beyond Git SHA comparisons.
  • [PERSISTENCE]: Modifies the agent's permanent installation to maintain functionality across restarts.
  • By installing and updating files in the agent's core skill directories, the skill achieves persistence for the new or modified code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:52 AM
Security Audit — agent-trust-hub — sn-update