zeabur-domain-register
Pass
Audited by Gen Agent Trust Hub on Apr 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Downloads the official Zeabur CLI from the public npm registry using
npx zeabur@latest. This is a vendor-owned resource used for its intended purpose.\n- [REMOTE_CODE_EXECUTION]: Executes the Zeabur CLI tool in the local environment to interact with domain management APIs, facilitating registry operations.\n- [COMMAND_EXECUTION]: Uses shell commands to perform domain lifecycle tasks, registrant profile updates, and ICANN verification status checks.\n- [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection. Ingestion points: Data returned from the CLI during domain listing and registration detail retrieval (file: SKILL.md). Boundary markers: None identified. Capability inventory: Subprocess execution via shell commands. Sanitization: No sanitization is specified for handling external data or user-supplied registrant details before command execution. This surface is considered a low risk inherent to the domain management use case.
Audit Metadata