sparkle-win
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as legitimate documentation for the WinSparkle framework. Its instructions and code examples align with standard development practices for software update systems.
- [EXTERNAL_DOWNLOADS]: The documentation references downloading the official WinSparkle binary and tools from its GitHub repository, which is the standard distribution channel for this well-known open-source project.
- [REMOTE_CODE_EXECUTION]: While the framework is designed to facilitate the execution of remote updates, the skill includes detailed security guidance to mitigate risks. It emphasizes the necessity of EdDSA (Ed25519) signatures and HTTPS to prevent unauthorized payload execution via Man-in-the-Middle attacks.
Audit Metadata