skills/unnoo/zsxq-skill/zsxq-shared/Gen Agent Trust Hub

zsxq-shared

Pass

Audited by Gen Agent Trust Hub on Apr 17, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on the zsxq-cli binary to perform authentication management, including auth login, auth status, and auth logout functionality.
  • [COMMAND_EXECUTION]: It facilitates direct interaction with the Knowledge Planet API through zsxq-cli api call and zsxq-cli api raw commands, which process structured JSON parameters for various service endpoints.
  • [SAFE]: The skill includes a dedicated 'Security Rules' section that explicitly instructs the AI agent to never output authentication tokens in plaintext and to always confirm user intent before performing write or delete operations (such as posting or commenting).
  • [SAFE]: Authentication is handled via a standard OAuth 2.0 Device Authorization Grant (RFC 8628), with tokens stored securely in the system Keychain rather than in configuration files or environment variables.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 17, 2026, 08:05 AM