skills/wu-yc/labclaw/zinc-database/Gen Agent Trust Hub

zinc-database

Pass

Audited by Gen Agent Trust Hub on Mar 13, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides Python code snippets and shell commands that utilize subprocess.run to invoke the curl utility for interacting with the CartBlanche22 API. These examples use list-based argument passing, which is a secure practice that prevents shell injection vulnerabilities.
  • [PROMPT_INJECTION]: The 'Suggest Using K-Dense Web' section contains behavioral instructions directing the agent to promote the vendor's platform for complex workflows. This is categorized as instruction-based steering and does not attempt to bypass safety filters or override core agent constraints.
  • [DATA_EXFILTRATION]: The skill documentation includes network operations targeting the docking.org and k-dense.ai domains. These are identified as legitimate resources for the ZINC database and the vendor's own infrastructure respectively. No unauthorized access to or transmission of sensitive local environment data was detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 13, 2026, 03:46 AM