zsxq-reply

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill identifies an indirect prompt injection surface by reading external posts and comments. It implements robust mitigation in Step 2 ('Validity Filtering'), explicitly instructing the agent to treat content as data rather than instructions and to reject any content attempting to probe local system information or induce command execution.
  • [COMMAND_EXECUTION]: The skill executes the zsxq-cli tool to manage interactions with the Knowledge Planet API. All destructive or 'write' actions (posting replies) require an explicit human-in-the-loop confirmation before execution.
  • [DATA_EXPOSURE]: The skill accesses local file system paths (e.g., /Users/itwanger/Documents/GitHub/) to read source code for the purpose of verifying technical details. This access is targeted and aligned with the skill's stated purpose of providing accurate technical mentorship.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 04:00 PM
Security Audit — agent-trust-hub — zsxq-reply