ziniao-openapi-explorer

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is designed to facilitate the execution of the ziniao-cli tool to interact with various API endpoints. Evidence: The documentation provides specific examples like ziniao-cli api /superbrowser/rest/v1/erp/per/role/list and includes a recommendation to use the --dry-run flag for safety.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface because it retrieves and potentially processes data from external API endpoints via ziniao-cli. Ingestion points: Data returned from the 73 available Ziniao API endpoints listed in the documentation. Boundary markers: There are no explicit delimiters or specific instructions for the agent to disregard commands embedded within the API output. Capability inventory: The agent is granted the ability to execute ziniao-cli commands for reading, creating, updating, and deleting records across departments, staff, accounts, and devices. Sanitization: No sanitization, validation, or filtering of the API-derived content is specified in the skill's instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 03:43 PM
Security Audit — agent-trust-hub — ziniao-openapi-explorer