zentao-productplan
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill uses a specific CLI tool for ZenTao interactions. Analysis of the command instructions and examples shows no evidence of hardcoded credentials, malicious network exfiltration, or unauthorized privilege escalation.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection. 1. Ingestion points: The agent ingests data from ZenTao plan names, codes, and descriptions via the output of the list and get commands in the reference files. 2. Boundary markers: There are no instructions or delimiters defined to prevent the agent from following instructions potentially embedded in the plan data. 3. Capability inventory: The skill allows for command execution via zentao-cli to create, update, and delete plans. 4. Sanitization: No data validation or sanitization is specified for the content retrieved from ZenTao before it is processed by the agent.
Audit Metadata