zentao-feedback
Pass
Audited by Gen Agent Trust Hub on May 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill uses a vendor-specific CLI tool to perform standard operations within the ZenTao platform.
- [INDIRECT_PROMPT_INJECTION]: The skill defines an interface that ingests data from the external ZenTao Feedback module, which could contain instructions intended to influence the agent.
- Ingestion points: Feedback titles, types, and descriptions retrieved via the list and get commands in
SKILL.md,references/zentao-feedback-list.md, andreferences/zentao-feedback-get.md. - Boundary markers: None specified in the reference documentation.
- Capability inventory: The skill has capabilities to create, modify, assign, close, and delete feedback records via various
zentao-cli feedbacksubcommands documented in thereferences/directory. - Sanitization: No explicit sanitization or validation of the content retrieved from the feedback system is described in the skill instructions.
Audit Metadata