command-guide
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill consists entirely of Markdown documentation and structural guidance for navigating the Claude Code ecosystem. It contains no executable scripts, shell commands, or network-enabled code.
- [INDIRECT_PROMPT_INJECTION]: The documentation defines auto-triggering rules (e.g., automatically invoking a 'code-reviewer' agent after code is written). While these rules attempt to influence agent behavior autonomously, they target standard, trusted built-in tools within the platform's intended design patterns.
- [DATA_EXPOSURE_AND_EXFILTRATION]: There are no patterns suggesting data exfiltration. The skill mentions a 'security-reviewer' agent to assist with sensitive data handling, which is a defensive measure rather than an attack vector.
- [COMMAND_EXECUTION]: While the skill documents various slash commands (like /plan, /tdd, /loop), it does not execute them or provide a mechanism for arbitrary command injection.
Audit Metadata