zentao-feedback

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues detected. The skill uses a vendor-specific CLI tool to perform standard operations within the ZenTao platform.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines an interface that ingests data from the external ZenTao Feedback module, which could contain instructions intended to influence the agent.
  • Ingestion points: Feedback titles, types, and descriptions retrieved via the list and get commands in SKILL.md, references/zentao-feedback-list.md, and references/zentao-feedback-get.md.
  • Boundary markers: None specified in the reference documentation.
  • Capability inventory: The skill has capabilities to create, modify, assign, close, and delete feedback records via various zentao-cli feedback subcommands documented in the references/ directory.
  • Sanitization: No explicit sanitization or validation of the content retrieved from the feedback system is described in the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 08:39 AM
Security Audit — agent-trust-hub — zentao-feedback