slash-command-factory

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill generates commands that interpolate user-supplied arguments directly into the instructions prompt without delimiters or sanitization.
  • Ingestion points: Where untrusted data enters agent context: The command_generator.py script takes user input (via answers['purpose'] and $ARGUMENTS) and interpolates it into the generated .md files.
  • Boundary markers (present/absent): Absent. The generated templates in command_generator.py (e.g., Execute task: "$ARGUMENTS") lack delimiters to isolate user input from the core command instructions.
  • Capability inventory: The generated commands are designed to use high-privilege tools such as Bash, Write, Edit, and Task (for launching other agents).
  • Sanitization (present/absent): Absent. The generation logic does not sanitize the input content or validate the safety of the strings being interpolated into the command instructions.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill encourages and generates commands using the !command`` syntax, which triggers shell execution at command load time.
  • The presets.json file and SKILL.md provide numerous examples and templates that automatically execute commands such as git status, find, tree, and du when the resulting slash command is loaded by Claude Code.
  • While the provided presets focus on benign development tasks, the skill teaches a pattern where shell operations are executed automatically without per-invocation user review.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 01:54 PM
Security Audit — agent-trust-hub — slash-command-factory