theme-update

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches update metadata and source code tarballs from the vendor's official GitHub repository (github.com/Weaverse/pilot). This is a well-known service and corresponds to the vendor's primary infrastructure.
  • [REMOTE_CODE_EXECUTION]: The skill downloads source code tarballs via curl and prepares them for execution through package installation and build commands. This behavior is documented and central to the theme update functionality.
  • [COMMAND_EXECUTION]: The skill executes shell commands for version detection, source extraction, and project building, including node, curl, git, and bun install.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes release notes from the GitHub API which are then used by the agent to plan and summarize updates.
  • Ingestion points: Release data is fetched via the GitHub API in scripts/check_pilot_updates.mjs and described in SKILL.md.
  • Boundary markers: No delimiters or warnings are used to isolate external release content from the instruction context.
  • Capability inventory: The skill can execute local commands (bun install, npm run build), write to the file system (cp, git apply), and make network requests (curl).
  • Sanitization: External release body text is not sanitized or filtered before being presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 12:16 PM
Security Audit — agent-trust-hub — theme-update