create-slash-commands
Warn
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: MEDIUMDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The main
SKILL.mdand reference files (e.g.,references/patterns.md) promote the use of the!commandsyntax to execute shell commands at load time. Examples include `! `git status,!npm test, and `! `gh pr diff $1. While the skill instructions often include a space after the exclamation mark in examples to prevent execution during analysis, the primary purpose of the skill is to teach users how to implement these dynamic executions. - [COMMAND_EXECUTION]: The skill encourages the creation of commands that execute various shell utilities, including
git,npm,grep, andgh. While it highlights the use ofallowed-toolsto restrict these operations, the underlying mechanism involves providing the agent with broad shell execution capabilities. - [INDIRECT_PROMPT_INJECTION]: The skill demonstrates patterns where untrusted user input is interpolated directly into shell commands, creating an injection surface.
- Ingestion points: Data enters the context via the
$ARGUMENTSstring and positional variables like$1,$2, and$3as described inreferences/arguments.md. - Boundary markers: The provided patterns do not include sanitization or boundary markers to prevent user-supplied arguments from breaking out of the intended command context.
- Capability inventory: The skill facilitates shell execution via the
Bashtool and dynamic context syntax. - Sanitization: There is no evidence of sanitization; for example,
!grep -r "TODO.*$ARGUMENTS" src/`` (found inSKILL.md) is vulnerable to command injection if$ARGUMENTScontains shell metacharacters like semicolons or backticks.
Audit Metadata