ziniao-department

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses ziniao-cli to perform department management, including administrative actions like creating, updating, and deleting departments. Deletion is noted as high-risk due to cascading effects to sub-departments and employees.\n- [PROMPT_INJECTION]: The skill instructions use strong imperative language (e.g., "CRITICAL", "MUST") to ensure the agent follows safety and authentication protocols defined in shared configuration files. While these look like injection patterns, they are used to enforce safety rather than bypass it.\n- [PROMPT_INJECTION]: The skill has an indirect prompt injection attack surface.\n
  • Ingestion points: Department names and IDs are ingested into the agent context through the output of ziniao-cli department list (referenced in SKILL.md and ziniao-department-list.md).\n
  • Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands within the retrieved department data.\n
  • Capability inventory: The skill possesses the capability to execute shell commands (ziniao-cli) that can modify or delete system data.\n
  • Sanitization: There is no evidence of sanitization or validation of the retrieved department names before they are processed or displayed.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 03:41 PM
Security Audit — agent-trust-hub — ziniao-department