zentao-bug
Pass
Audited by Gen Agent Trust Hub on May 20, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill facilitates interaction with the ZenTao API through the
zentao-clibinary. This is standard behavior for an integration skill of this type. - [EXTERNAL_DOWNLOADS]: The skill specifies
zentao-clias a required binary in its metadata. This is a system-level dependency for the skill to function. - [PROMPT_INJECTION]: The skill processes bug details, including titles and reproduction steps, which are sourced from external data (ZenTao). This constitutes an indirect prompt injection surface typical of bug tracking integrations, though no malicious instructions are present in the skill code.
Audit Metadata