skills/zenmux/skills/zenmux-feedback/Gen Agent Trust Hub

zenmux-feedback

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill clones the vendor's official documentation repository (github.com/ZenMux/zenmux-doc) to retrieve the latest GitHub issue templates.
  • [COMMAND_EXECUTION]: The skill utilizes several system commands to perform its tasks:
  • Executes git to clone and pull updates for reference materials.
  • Uses the GitHub CLI (gh) to verify authentication status and create issues on the remote repository.
  • Runs local shell scripts (scripts/update-references.sh, scripts/get-doc-tree.sh) for environment setup and documentation indexing.
  • [DYNAMIC_EXECUTION]: The scripts/update-references.sh file uses a python3 one-liner to dynamically calculate relative paths between the project root and the references directory. This is used for correctly updating the project's .gitignore file.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a conduit for user-provided data and external templates, creating a vulnerability surface for indirect prompt injection.
  • Ingestion points: User chat input containing feedback/bug descriptions and .yml template files from the ZenMux/zenmux-doc repository.
  • Boundary markers: Absent. The skill does not use specific delimiters or warnings to prevent the model from following instructions embedded in the feedback content.
  • Capability inventory: File system access (reading templates, writing to /tmp, modifying .gitignore) and network access (GitHub API via gh).
  • Sanitization: The skill employs a secure practice of writing the issue body to a temporary file (/tmp/zenmux-issue-body.md) and passing it to the CLI via a file flag, preventing shell injection from user-controlled strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:44 PM
Security Audit — agent-trust-hub — zenmux-feedback