skills/iamzifei/zmm/zmm-script/Gen Agent Trust Hub

zmm-script

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using Python 3 to maintain its internal data structures and retrieve writing materials.
  • Evidence: python3 scripts/rebuild_published_index.py (SKILL.md) and surface_candidates.py --kw (SKILL.md).
  • [DYNAMIC_EXECUTION]: The agent is tasked with running local Python scripts at runtime to process vault data and generate candidate materials for the user.
  • Evidence: Phase 2 and Phase 6 of the workflow involve script-based processing of the content repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection because it ingests untrusted data from an external vault and user-provided topics.
  • Ingestion points: Reads content from the {vault} directory, specifically from 06-选题装配/选题管道.md and 02-内容单元库/.
  • Boundary markers: The instructions lack explicit delimitation or "ignore embedded instructions" tags when processing external vault files.
  • Capability inventory: The skill has the ability to write to the file system (_草稿/ and 02-内容单元库/) and execute shell commands (python3).
  • Sanitization: The skill includes a manual verification step in Phase 2, instructing the agent to check AI-generated facts against a specific 知识库/AI参考/ and to mask sensitive financial information.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:43 AM