theme-update
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches update metadata and source code tarballs from the vendor's official GitHub repository (
github.com/Weaverse/pilot). This is a well-known service and corresponds to the vendor's primary infrastructure. - [REMOTE_CODE_EXECUTION]: The skill downloads source code tarballs via
curland prepares them for execution through package installation and build commands. This behavior is documented and central to the theme update functionality. - [COMMAND_EXECUTION]: The skill executes shell commands for version detection, source extraction, and project building, including
node,curl,git, andbun install. - [INDIRECT_PROMPT_INJECTION]: The skill processes release notes from the GitHub API which are then used by the agent to plan and summarize updates.
- Ingestion points: Release data is fetched via the GitHub API in
scripts/check_pilot_updates.mjsand described inSKILL.md. - Boundary markers: No delimiters or warnings are used to isolate external release content from the instruction context.
- Capability inventory: The skill can execute local commands (
bun install,npm run build), write to the file system (cp,git apply), and make network requests (curl). - Sanitization: External release body text is not sanitized or filtered before being presented to the agent.
Audit Metadata