ai-coding-agents-command-runtime
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a system for discovering, parsing, and executing slash-commands from local files and third-party plugins, which could be used as an entry point for malicious instructions if the source files are compromised.
- Ingestion points: Command definitions and prompt content are read from disk locations including
.claude/commands/,~/.claude/commands/, and plugin-specific directories as described inreferences/memoization-invalidation-contract.mdandassets/templates/minimal-command-registry.ts. - Boundary markers: While the architecture uses a typed command contract, there is no evidence of strict content sanitization or boundary markers (e.g., delimiters or 'ignore' warnings) to prevent the agent from following malicious instructions embedded within the loaded command prompt files.
- Capability inventory: The system supports high-privilege capabilities including file system access, subagent forking, and command execution across local and remote contexts (
references/command-dispatch-forking-and-remote-safety.md). - Sanitization: The implementation templates focus on precedence and lazy loading but do not include mechanisms to validate or sanitize the natural language prompt content before it is processed by the agent.
Audit Metadata