zenmux-feedback
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill clones the vendor's official documentation repository (
github.com/ZenMux/zenmux-doc) to retrieve the latest GitHub issue templates. - [COMMAND_EXECUTION]: The skill utilizes several system commands to perform its tasks:
- Executes
gitto clone and pull updates for reference materials. - Uses the GitHub CLI (
gh) to verify authentication status and create issues on the remote repository. - Runs local shell scripts (
scripts/update-references.sh,scripts/get-doc-tree.sh) for environment setup and documentation indexing. - [DYNAMIC_EXECUTION]: The
scripts/update-references.shfile uses apython3one-liner to dynamically calculate relative paths between the project root and the references directory. This is used for correctly updating the project's.gitignorefile. - [INDIRECT_PROMPT_INJECTION]: The skill acts as a conduit for user-provided data and external templates, creating a vulnerability surface for indirect prompt injection.
- Ingestion points: User chat input containing feedback/bug descriptions and
.ymltemplate files from theZenMux/zenmux-docrepository. - Boundary markers: Absent. The skill does not use specific delimiters or warnings to prevent the model from following instructions embedded in the feedback content.
- Capability inventory: File system access (reading templates, writing to
/tmp, modifying.gitignore) and network access (GitHub API viagh). - Sanitization: The skill employs a secure practice of writing the issue body to a temporary file (
/tmp/zenmux-issue-body.md) and passing it to the CLI via a file flag, preventing shell injection from user-controlled strings.
Audit Metadata