zentao-tour
Pass
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing
zentao-clivia common package managers (npm,pnpm,bun). This tool is the official CLI for the ZenTao platform and is maintained by the skill's author, easysoft. - [COMMAND_EXECUTION]: The agent is instructed to use
zentao-clito perform CRUD (Create, Read, Update, Delete) operations on ZenTao project data. These actions are performed to simulate real-world workflows for the user during the tour. - [CREDENTIALS_UNSAFE]: The skill mentions the storage location of user credentials in the
~/.config/zentao/zentao.jsonfile. This is standard configuration information for thezentao-clitool and is used to verify connectivity and authentication during the setup process. - [PROMPT_INJECTION]: The skill processes data retrieved from the ZenTao server, creating a potential surface for indirect prompt injection.
- Ingestion points: Data enters the agent context through
zentao task,zentao bug, andzentao storycommand outputs (referenced inroles/dev.md,roles/test.md, androles/pm.md). - Boundary markers: The instructions do not define specific delimiters or warnings to ignore instructions embedded in the project data.
- Capability inventory: The skill possesses write capabilities through
zentao create,update,resolve, andclosecommands across all role-based scripts. - Sanitization: There is no explicit sanitization or filtering of the content retrieved from the external ZenTao instance.
Audit Metadata