command-development

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMMETADATA_POISONINGINDIRECT_PROMPT_INJECTIONSAFE
Full Analysis
  • [METADATA_POISONING]: The skill manifest file skill-report.json contains deceptive metadata claiming the author is 'anthropics' and that the content is 'official'. This contradicts the provided author context of 'aiskillstore', suggesting an attempt to impersonate official documentation.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents and encourages patterns for building commands that ingest untrusted user input ($ARGUMENTS) and file content (@ syntax) into AI instructions.
  • Ingestion points: Described in SKILL.md (Dynamic Arguments and File References sections).
  • Boundary markers: The skill provides specific 'Validation Patterns' (e.g., using grep to check environment names) and 'Best Practices' to mitigate risks.
  • Capability inventory: Documents the use of bash execution (!` syntax) and file system read tools.
  • Sanitization: Includes a dedicated 'Validation Patterns' section in SKILL.md and references/plugin-features-reference.md to guide developers in filtering external content.
  • [SAFE]: The technical content is purely educational documentation. Static analysis signals regarding destructive commands in references/testing-strategies.md are false positives; they refer to example test cases (such as demonstrating how a forbidden ls -la / command is handled) and the use of dd to create non-sensitive dummy files for testing purposes.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 11:53 PM