slash-command-factory
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill generates commands that interpolate user-supplied arguments directly into the instructions prompt without delimiters or sanitization.
- Ingestion points: Where untrusted data enters agent context: The
command_generator.pyscript takes user input (viaanswers['purpose']and$ARGUMENTS) and interpolates it into the generated.mdfiles. - Boundary markers (present/absent): Absent. The generated templates in
command_generator.py(e.g.,Execute task: "$ARGUMENTS") lack delimiters to isolate user input from the core command instructions. - Capability inventory: The generated commands are designed to use high-privilege tools such as
Bash,Write,Edit, andTask(for launching other agents). - Sanitization (present/absent): Absent. The generation logic does not sanitize the input content or validate the safety of the strings being interpolated into the command instructions.
- [DYNAMIC_CONTEXT_INJECTION]: The skill encourages and generates commands using the
!command`` syntax, which triggers shell execution at command load time. - The
presets.jsonfile andSKILL.mdprovide numerous examples and templates that automatically execute commands such asgit status,find,tree, andduwhen the resulting slash command is loaded by Claude Code. - While the provided presets focus on benign development tasks, the skill teaches a pattern where shell operations are executed automatically without per-invocation user review.
Audit Metadata