qzcli
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Downloads the qzcli_tool CLI from an external, untrusted GitHub repository (https://github.com/tianyilt/qzcli_tool) not associated with a known trusted vendor.\n- [REMOTE_CODE_EXECUTION]: The installation process for the tool uses pip install -e . on the downloaded repository, which executes potentially untrusted build logic and code at installation time.\n- [CREDENTIALS_UNSAFE]: The documentation provides examples of passing sensitive passwords as plain-text command-line arguments (e.g., qzcli login -u USER -p 'PASSWORD'), which can expose credentials in process lists, shell history, and logs.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from the Qizhi platform (Ingestion points: qzcli ls, qzcli status, qzcli watch) without explicit boundary markers or sanitization, potentially allowing malicious content in job logs or statuses to influence agent behavior. The skill has broad capabilities via Bash(*) (Capability inventory).
Audit Metadata