zero-chat
Pass
Audited by Gen Agent Trust Hub on Apr 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill connects to api.vm0.ai, which is the official API domain for the vendor vm0-ai.
- [SAFE]: Credentials are managed using the $ZERO_API_KEY environment variable, which is a secure and recommended practice.
- [COMMAND_EXECUTION]: The zero-curl wrapper script executes the system curl command. It uses the shell variable "$@" to pass arguments, which prevents argument splitting or injection vulnerabilities.
Audit Metadata