Skills zentao-task-planner
📦

zentao-task-planner

Content revision r2 High Risk 🌐 Network access📁 Filesystem access🔑 Env variables Contains scripts⚙️ External commands

Plan and Manage Zentao Tasks

Weekly planning often produces inconsistent tasks and manual Zentao updates. This skill structures schedules and previews supported task operations before execution.

Supports: Claude Codex Code(CC)
⚠️ 38 Poor

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "zentao-task-planner" from https://skillstore.io/skills/ariesyb-zentao-task-planner.md and its manifest at https://skillstore.io/api/skills/ariesyb-zentao-task-planner/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "zentao-task-planner". Plan next week for requirement 103615 with forty available hours.

Expected outcome:

A dated work plan divides research, development, testing, and review into tasks between two and eight hours.

Using "zentao-task-planner". Show my active tasks with common fields only.

Expected outcome:

The summary lists each task identifier, name, status, priority, assignee, planned hours, consumed hours, remaining hours, and dates.

Using "zentao-task-planner". Close all finished tasks.

Expected outcome:

A preview lists the matched finished tasks and requests confirmation before any task is closed.

Security Audit

High Risk
v7 • 8/20/2026 Open versioned report

Most static alerts are false positives caused by Markdown formatting, Chinese text entropy, local configuration documentation, and ordinary Zentao identifier parsing. The client has two confirmed transport risks: it permits plaintext HTTP and does not enforce its origin boundary across redirects.

20
Files scanned
2,191
Lines analyzed
0
Review items
0
False positives ignored

Confirmed security concerns (2)

High
Plain HTTP Can Expose Zentao Credentials
The client accepts HTTP base URLs, then submits the Zentao account and password to the login endpoint without transport encryption.
The scheme check explicitly permits http://, and the login method directly posts both credential fields to that configured origin.
High
Redirects Can Bypass the Configured Network Boundary
Requests follows redirects by default, but the client validates only the initial URL. A cross-origin redirect can leave the configured Zentao origin.
The initial URL receives a prefix check, while the session request does not disable redirects or validate the final response URL and redirect history.
Audited by: codex View Audit History →
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/ariesyb-zentao-task-planner/audits/7?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/ariesyb-zentao-task-planner/security.svg)](https://skillstore.io/skills/ariesyb-zentao-task-planner?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/ariesyb-zentao-task-planner?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/ariesyb-zentao-task-planner/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/ariesyb-zentao-task-planner.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA · BibTeX · CFF)

APA citation

ariesyb. (2026). zentao-task-planner security audit report (audit version 7) [Author version unspecified]. Skillstore. https://skillstore.io/skills/ariesyb-zentao-task-planner/audits/7

BibTeX citation

@techreport{ariesyb-ariesyb-zentao-task-planner-2026, author = {ariesyb}, title = {zentao-task-planner security audit report (audit version 7)}, institution = {Skillstore}, year = {2026}, number = {7}, url = {https://skillstore.io/skills/ariesyb-zentao-task-planner/audits/7}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "zentao-task-planner security audit report (audit version 7)" version: "unspecified" type: report authors: - name: "ariesyb" date-released: "2026-08-20" url: "https://skillstore.io/skills/ariesyb-zentao-task-planner/audits/7" identifiers: - type: other value: "skillstore:ariesyb-zentao-task-planner:audit:7" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
68
Architecture
85
Maintainability
87
Content
68
Community
83
Spec Compliance

What You Can Build

Prepare a Weekly Plan

Turn requirements and available workdays into a balanced task schedule with consistent fields.

Review Team Workloads

List assigned tasks and compare planned hours, dates, status, and remaining work.

Maintain Zentao Records

Preview task creation, completion, closure, or date repairs before approved execution.

Try These Prompts

List My Tasks
List my active Zentao tasks in a concise summary. Do not perform any write operation.
Plan Next Week
Plan my next workweek for requirement [ID]. Ask for missing details, use actual workdays, and keep each task between two and eight hours.
Preview Task Creation
Validate this task plan and preview the Zentao tasks that would be created. Report errors and wait for confirmation.
Repair a Completion Date
Preview repair of task [ID]. Show the deadline, affected effort records, assignee, and proposed changes without executing them.

Best Practices

  • Use HTTPS and provide credentials through protected process environment variables.
  • Review every preview and confirm task identifiers, dates, assignees, and hours.
  • Keep local credential files outside version control and skill packages.

Avoid

  • Do not execute a write operation without reviewing the preview.
  • Do not use plaintext HTTP for any Zentao account with real credentials.
  • Do not assume workdays, requirement identifiers, task types, or assignees.

Frequently Asked Questions

Does this skill create Zentao tasks automatically?
It previews validated tasks first. Actual creation requires the execute flag after user confirmation.
Which credentials are required?
Provide the Zentao base URL, account, and password through process variables or an explicit local environment file.
Can it plan around holidays?
Yes. It uses the Chinese calendar library when available and otherwise falls back to weekdays.
Which task views can it list?
It supports active, assigned, finished, and closed task views exposed by the configured Zentao instance.
Can it correct an incorrect completion date?
Yes. It previews activation and effort-date changes, then requires explicit execution.
Does it send data to third-party services?
The code targets the configured Zentao site only, but redirect handling must be hardened before relying on that boundary.

Developer Details

Author

ariesyb

License

MIT

Skillstore revision

r2

Version notice

The author did not declare a version.

Ref

7b0e7cf67446844ab9bf2218247856d49e498720

Maintenance freshness

8/20/2026

Usage

4 downloads · 97 views

More from ariesyb

View all
View all