command-development
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides educational documentation and best practices for developing slash commands. It explicitly instructs developers to follow the principle of least privilege by using restrictive
allowed-toolssettings and provides guidance on securing commands against misuse. - [COMMAND_EXECUTION]: The documentation describes the use of the
!command`` syntax for dynamic context gathering in slash commands. All examples provided in the skill and its references are pedagogical, using standard development tools likegit,npm, andkubectlto illustrate intended functionality. - [INDIRECT_PROMPT_INJECTION]: The skill addresses the potential for prompt injection via user-supplied arguments and file references. It provides a dedicated "Validation Patterns" section that teaches developers how to implement sanitization, existence checks, and validation logic to safely handle untrusted data.
- [SAFE]: Deterministic detections for potentially risky commands in
references/testing-strategies.mdwere evaluated and determined to be benign. Theddandrmcommands are used in a standard testing context to manage temporary files in/tmp, and other shell commands are part of negative test cases designed to verify platform-enforced security boundaries.
Audit Metadata