create-slash-commands

Warn

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: MEDIUMDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The main SKILL.md and reference files (e.g., references/patterns.md) promote the use of the ! command syntax to execute shell commands at load time. Examples include `! `git status, ! npm test, and `! `gh pr diff $1. While the skill instructions often include a space after the exclamation mark in examples to prevent execution during analysis, the primary purpose of the skill is to teach users how to implement these dynamic executions.
  • [COMMAND_EXECUTION]: The skill encourages the creation of commands that execute various shell utilities, including git, npm, grep, and gh. While it highlights the use of allowed-tools to restrict these operations, the underlying mechanism involves providing the agent with broad shell execution capabilities.
  • [INDIRECT_PROMPT_INJECTION]: The skill demonstrates patterns where untrusted user input is interpolated directly into shell commands, creating an injection surface.
  • Ingestion points: Data enters the context via the $ARGUMENTS string and positional variables like $1, $2, and $3 as described in references/arguments.md.
  • Boundary markers: The provided patterns do not include sanitization or boundary markers to prevent user-supplied arguments from breaking out of the intended command context.
  • Capability inventory: The skill facilitates shell execution via the Bash tool and dynamic context syntax.
  • Sanitization: There is no evidence of sanitization; for example, ! grep -r "TODO.*$ARGUMENTS" src/`` (found in SKILL.md) is vulnerable to command injection if $ARGUMENTS contains shell metacharacters like semicolons or backticks.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 30, 2026, 01:24 PM