command-creator

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill documents and utilizes the !command syntax, which allows shell command execution and output injection into prompts. It includes an example template (/issues) that passes user-provided arguments directly into a shell command (gh issue list --search "$ARGUMENTS"), representing a command injection risk if input is not sanitized.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to build command templates that ingest untrusted external data. Ingestion points: Templates interpolate user arguments ($ARGUMENTS), shell command results (!command), and file contents (@filename). Boundary markers: The skill recommends using dedicated XML blocks (e.g., <user_guidelines>) to separate instructions from untrusted content. Capability inventory: The generated commands have capabilities for shell execution and file system access. Sanitization: The skill does not provide instructions for validating or escaping the interpolated data.
  • [COMMAND_EXECUTION]: The skill demonstrates the use of local shell utilities such as git status, git diff, and ls to provide context to the agent. These are standard developer tools used for legitimate contextual analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:49 PM