command-development
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMMETADATA_POISONINGINDIRECT_PROMPT_INJECTIONSAFE
Full Analysis
- [METADATA_POISONING]: The skill manifest file
skill-report.jsoncontains deceptive metadata claiming the author is 'anthropics' and that the content is 'official'. This contradicts the provided author context of 'aiskillstore', suggesting an attempt to impersonate official documentation. - [INDIRECT_PROMPT_INJECTION]: The skill documents and encourages patterns for building commands that ingest untrusted user input ($ARGUMENTS) and file content (@ syntax) into AI instructions.
- Ingestion points: Described in
SKILL.md(Dynamic Arguments and File References sections). - Boundary markers: The skill provides specific 'Validation Patterns' (e.g., using grep to check environment names) and 'Best Practices' to mitigate risks.
- Capability inventory: Documents the use of bash execution (!` syntax) and file system read tools.
- Sanitization: Includes a dedicated 'Validation Patterns' section in
SKILL.mdandreferences/plugin-features-reference.mdto guide developers in filtering external content. - [SAFE]: The technical content is purely educational documentation. Static analysis signals regarding destructive commands in
references/testing-strategies.mdare false positives; they refer to example test cases (such as demonstrating how a forbiddenls -la /command is handled) and the use ofddto create non-sensitive dummy files for testing purposes.
Audit Metadata