skills/leeguooooo/zentao-mcp/zentao/Gen Agent Trust Hub

zentao

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the @leeguoo/zentao-mcp Node.js package from the NPM registry to provide the zentao command-line interface. This package is a vendor resource associated with the skill author.
  • [COMMAND_EXECUTION]: The skill leverages the zentao CLI to interact with ZenTao instances, performing operations such as record lookup, creation, and status updates.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data that could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: The skill retrieves and displays data from ZenTao, including bug titles, task descriptions, story specifications, and user comments from the SKILL.md context.
  • Boundary markers: The instructions do not define specific delimiters or "ignore instructions" markers when handling data returned from the ZenTao instance.
  • Capability inventory: The skill possesses the ability to execute various state-changing commands on the ZenTao instance, such as creating, resolving, or closing bugs and tasks.
  • Sanitization: No explicit sanitization or content validation steps are documented for the data ingested from the external ZenTao platform.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:56 AM
Security Audit — agent-trust-hub — zentao