skills/imyuyu/zentao-cli/zentao-bug/Gen Agent Trust Hub

zentao-bug

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill presents a surface for indirect prompt injection by processing external data from the ZenTao bug tracking system.
  • Ingestion points: The skill retrieves bug titles, descriptions, and reproduction steps using zentao-cli bug get and zentao-cli bug list as documented in references/zentao-bug-get.md and references/zentao-bug-list.md.
  • Boundary markers: The instructions do not define delimiters or specific 'ignore' directives to prevent the agent from executing instructions found within the bug data.
  • Capability inventory: The skill possesses several sensitive capabilities, including creating, updating, resolving, and deleting bugs via the zentao-cli commands.
  • Sanitization: There is no evidence of sanitization or validation logic to filter out potentially malicious prompt content from the ingested bug reports.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:26 AM
Security Audit — agent-trust-hub — zentao-bug