zentao-api
Manage ZenTao Projects Through the API
Teams need fast access to ZenTao work items without manually building API requests. This skill maps natural language requests to ZenTao REST API v2.0 calls.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "zentao-api" from https://skillstore.io/skills/easysoft-zentao-api.md and its manifest at https://skillstore.io/api/skills/easysoft-zentao-api/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "zentao-api". Show active projects and their executions.
Expected outcome:
A concise project list with IDs, active execution names, status, owners, and next lookup suggestions.
Using "zentao-api". Create a critical bug for product 12.
Expected outcome:
A confirmation summary showing target product, title, severity, build, assignee, and the exact fields that will be submitted.
Using "zentao-api". Resolve bug 345 as fixed.
Expected outcome:
A status update that confirms the resolved bug, resolution value, server response summary, and any follow-up fields.
Security Audit
High RiskThe skill is a legitimate ZenTao REST API helper, and many static hits are Markdown code spans or intended API examples. Confirmed issues are the eval-based token helper and plaintext persistent token cache in ~/.zentao-token.json. These can expose long-lived credentials and enable shell execution from malicious token values.
Confirmed security concerns (2)
Capability review items (21)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (80)
📁 Filesystem access (15)
🌐 Network access (4)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/easysoft-zentao-api/audits/4?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/easysoft-zentao-api?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/easysoft-zentao-api?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/easysoft-zentao-api/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/easysoft-zentao-api.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA · BibTeX · CFF)
APA citation
easysoft. (2026). zentao-api security audit report (audit version 4) [Author version 1.0.4]. Skillstore. https://skillstore.io/skills/easysoft-zentao-api/audits/4BibTeX citation
@techreport{easysoft-easysoft-zentao-api-2026,
author = {easysoft},
title = {zentao-api security audit report (audit version 4)},
institution = {Skillstore},
year = {2026},
number = {4},
url = {https://skillstore.io/skills/easysoft-zentao-api/audits/4},
note = {Author version 1.0.4}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "zentao-api security audit report (audit version 4)"
version: "1.0.4"
type: report
authors:
- name: "easysoft"
date-released: "2026-07-06"
url: "https://skillstore.io/skills/easysoft-zentao-api/audits/4"
identifiers:
- type: other
value: "skillstore:easysoft-zentao-api:audit:4"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Review Delivery Status
Review active projects, executions, and blocked work without manually composing API URLs.
Triage Bugs and Test Work
Create, filter, resolve, or close bugs and test records using consistent ZenTao fields.
Maintain Sprint Tasks
Update tasks, requirements, builds, and releases while preserving required workflow fields.
Try These Prompts
Show active ZenTao projects and list their active executions. Include names, IDs, owners, and current status.
Find open bugs for product 12. Sort newest first and summarize severity, assignee, and title.
Prepare a new bug for product 12 with title, severity, build, and assigned owner. Ask me to confirm before creating it.
Review project 8 bugs, tasks, and builds. Propose release actions, then confirm each ZenTao write operation before execution.
Best Practices
- Set ZENTAO_URL and ZENTAO_TOKEN in environment variables before use.
- Confirm all create, update, delete, and status-change operations.
- Review required fields in the API reference before sending write requests.
Avoid
- Do not paste permanent tokens into chat transcripts.
- Do not run destructive changes without confirming target IDs.
- Do not rely on default grade values when creating Story, Epic, or Requirement records.
Frequently Asked Questions
What does this skill connect to?
Does it need credentials?
Can it change ZenTao records?
Which modules are covered?
Does it support Claude, Codex, and Claude Code?
How does authentication work?
Developer Details
Author
easysoftLicense
MIT
Author version
v1.0.4
Skillstore revision
r1
Ref
72d5025b022c77f7a51bdf5c1637c689c80e89d1
Maintenance freshness
7/18/2026
Usage
3 downloads · 89 views
File structure