zul-writer

Pass

Audited by Gen Agent Trust Hub on Mar 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's validation logic in 'scripts/validate-zul.py' fetches XML Schema Definitions (XSD) from the official ZK Framework domain (zkoss.org), which is a well-known technology provider. This operation is documented neutrally as it serves the legitimate purpose of verifying XML structure.
  • [SAFE]: The Python validation utility utilizes the reputable 'lxml' package and standard libraries for XML parsing and ZK 10 compatibility checks. No evidence of unauthorized command execution, dynamic code loading from untrusted sources, or data exfiltration was found.
  • [SAFE]: Evaluation of the instructions and assets confirms the absence of prompt injection attempts, obfuscated content, persistence mechanisms, or hardcoded credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 11, 2026, 08:39 AM