plugin-commands

Warn

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the dynamic context injection pattern (!command) to execute shell commands (bash, node, git, cat) automatically when the command files are processed by the agent. This execution happens at the 'load' phase before standard tool-use confirmation prompts.
  • [COMMAND_EXECUTION]: Multiple templates, including 'analyze.md', 'full-audit.md', and 'build-env.md', pass user-supplied arguments ($1) directly into shell command strings. This pattern is vulnerable to command injection. If a user provides an argument containing shell metacharacters (e.g., semicolons, backticks, or pipes), they may be able to execute arbitrary commands within the agent's environment.
  • [REMOTE_CODE_EXECUTION]: The skill facilitates the execution of local scripts found in the plugin's root directory. While these scripts are part of the plugin itself, the use of !command enables automated execution of these scripts as soon as the agent accesses the skill, potentially bypassing manual oversight.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 16, 2026, 11:14 AM
Security Audit — agent-trust-hub — plugin-commands