command-development
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides extensive documentation and examples for using the
!command`` syntax to execute shell commands within slash commands. These examples are used for gathering repository context (e.g.,git status), running tests (e.g.,npm test), and managing deployments (e.g.,kubectl). All instances are educational and align with standard platform features. - [REMOTE_CODE_EXECUTION]: The documentation describes how to execute local plugin scripts using the
${CLAUDE_PLUGIN_ROOT}environment variable. It explicitly includes validation patterns, such as checking for file existence and validating input arguments withgrep, to encourage secure development practices. - [SAFE]: A static analysis hit for destructive commands was identified in
references/testing-strategies.mddue to addcommand. However, this is a false positive; the command is used to generate a dummy 100MB file (/tmp/large-file.bin) to teach developers how to test the agent's handling of large file references. - [SAFE]: The skill uses standard Claude Code platform tools like
Read,Write, andBashwithin its educational templates. It recommends the principle of least privilege by suggesting users restrict bash tool access to specific commands (e.g.,Bash(git:*)).
Audit Metadata