zsxq-topic
Pass
Audited by Gen Agent Trust Hub on May 12, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
zsxq-clibinary to interact with the Knowledge Planet API for topic management. This includes operations for searching, viewing, creating, replying to, and deleting topics. - [PROMPT_INJECTION]: The skill identifies a potential indirect prompt injection surface where user-provided content (titles, text, queries) is passed to CLI commands. It mitigates this risk by explicitly instructing the agent to confirm the content and target星球/主题 with the user before performing any write or delete operations.
- [SAFE]: All external resources and command patterns are consistent with the skill's stated purpose of managing Knowledge Planet topics via a vendor-specific CLI tool (
zsxq-cli).
Audit Metadata