zensical
Fail
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [METADATA_POISONING]: The skill makes deceptive and likely false assertions, claiming to be the official successor to 'Material for MkDocs' and developed by the same team. This framing appears intended to build unearned trust and encourage the use of unverified software.
- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The documentation directs users and agents to install a package named 'zensical' via pip and execute a corresponding Docker image. These resources are not associated with the legitimate maintainers of the referenced project and their safety cannot be verified.
- [COMMAND_EXECUTION]: The skill provides instructions for running system-level commands through a tool with a suspicious and unverifiable origin, which could facilitate unauthorized actions on the host machine.
- [INDIRECT_PROMPT_INJECTION]: The Zensical tool documented in this skill ingests untrusted Markdown files and configuration data. Ingestion points: Markdown source files in the docs directory and zensical.toml. Boundary markers: Absent. Capability inventory: Local file system read via the Snippets extension and CLI command execution. Sanitization: Absent.
Recommendations
- AI detected serious security threats
Audit Metadata