zsxq-reply
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill identifies an indirect prompt injection surface by reading external posts and comments. It implements robust mitigation in Step 2 ('Validity Filtering'), explicitly instructing the agent to treat content as data rather than instructions and to reject any content attempting to probe local system information or induce command execution.
- [COMMAND_EXECUTION]: The skill executes the
zsxq-clitool to manage interactions with the Knowledge Planet API. All destructive or 'write' actions (posting replies) require an explicit human-in-the-loop confirmation before execution. - [DATA_EXPOSURE]: The skill accesses local file system paths (e.g.,
/Users/itwanger/Documents/GitHub/) to read source code for the purpose of verifying technical details. This access is targeted and aligned with the skill's stated purpose of providing accurate technical mentorship.
Audit Metadata