Command DevelopmentCAUTION
Semi-automated research assistant for academic research and software development. Supports Claude Code, Codex CLI, Kimi Code CLI, and OpenCode across ideation, coding, experiments, writing, and publication.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Comprehensive guidance on creating Claude Code slash commands, including file format, frontmatter options, dynamic arguments, and best practices.
Overview
This skill provides knowledge about:
- Slash command file format and structure
- YAML frontmatter configuration fields
- Dynamic arguments ($ARGUMENTS, $1, $2, etc.)
- File references with @ syntax
- Bash execution with !` syntax
- Command organization and namespacing
- Best practices for command development
- Plugin-specific features (${CLAUDEPLUGINROOT}, plugin patterns)
- Integration with plugin components (agents, skills, hooks)
- Validation patterns and error handling
Skill Structure
SKILL.md (~2,470 words)
Core skill content covering:
Fundamentals:
- Command basics and locations
- File format (Markdown with optional frontmatter)
- YAML frontmatter fields overview
- Dynamic arguments ($ARGUMENTS and positional)
- File references (@ syntax)
- Bash execution (!` syntax)
- Command organization patterns
- Best practices and common patterns
- Troubleshooting
Plugin-Specific:
- ${CLAUDEPLUGINROOT} environment variable
- Plugin command discovery and organization
- Plugin command patterns (configuration, template, multi-script)
- Integration with plugin components (agents, skills, hooks)
- Validation patterns (argument, file, resource, error handling)
References
Detailed documentation:
- frontmatter-reference.md: Complete YAML frontmatter field specifications
- All field descriptions with types and defaults
- When to use each field
- Examples and best practices
- Validation and common errors
- plugin-features-reference.md: Plugin-specific command features
- Plugin command discovery and organization
- ${CLAUDEPLUGINROOT} environment variable usage
- Plugin command patterns (configuration, template, multi-script)
- Integration with plugin agents, skills, and hooks
- Validation patterns and error handling
Examples
Practic
29ad4d4206fbOBSERVED · 2026-10-07Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: command-development description: This skill should be used when the user asks to "create a slash command", "add a command", "write a custom command", "define command arguments", "use command frontmatter", "organize commands", "create command with file references", "interactive command", "use AskUserQuestion in command", or needs guidance on slash command structure, YAML frontmatter fields, dynamic arguments, bash execution in commands, user interaction patterns, or command development best practices for Claude Code. version: 0.2.0 --- # Command Development for Claude Code ## Overview Slash commands are frequently-used prompts defined as Markdown files that Claude executes during interactive sessions. Understanding command structure, frontmatter options, and dynamic features enables creating powerful, reusable workflows. **Key concepts:** - Markdown file format for commands - YAML frontmatter for configuration - Dynamic arguments and file references - Bash execution for context - Command organization and namespacing ## Command Basics ### What is a Slash Command? A slash command is a Markdown file containing a prompt that Claude executes when invoked. Commands provide: - **Reusability**: Define once, use repeatedly - **Consistency**: Standardize common workflows - **Sharing**: Distribute across team or projects - **Efficiency**: Quick access to complex prompts ### Critical: Commands are Instructions FOR Claude **Commands are written for agent consumption, not human consumption.** When a user invokes `/command-name`, the command content becomes Claude's instructions. Write commands as directives TO Claude about what to do, not as messages TO the user. **Correct approach (instructions for Claude):** ```markdown Review this code for security vulnerabilities including: - SQL injection - XSS attacks - Authentication issues Provide specific line numbers and severity ratings. ``` **Incorrect approach (messages to user):** ```markdown This command will review your code for security issues. You'll receive a report with vulnerability details. ``` The first example tells Claude what to do. The second tells the user what will happen but doesn't instruct Claude. Always use the first approach. ### Command Locations **Project commands** (shared with team): - Location: `.claude/commands/` - Scope: Available in specific project - Label: Shown as "(project)" in `/help` - Use for: Team workflows, project-specific tasks **Personal commands** (available everywhere): - Location: `~/.claude/commands/` - Scope: Available in all projects - Label: Shown as "(user)" in `/help` - Use for: Personal workflows, cross-project utilities **Plugin commands** (bundled with plugins): - Location: `plugin-name/commands/` - Scope: Available when plugin installed - Label: Shown as "(plugin-name)" in `/help` - Use for: Plugin-specific functionality ## File Format ### Basic Structure Commands are Markdown files with `.md` extension: ``` .claude/commands/ ├── review.md # /review command ├── test.md # /test command └── deploy.md # /deploy command ``` **Simple command:** ```markdown Review this code for security vulnerabilities including: - SQL injection - XSS attacks - Authentication bypass - Insecure data handling ``` No frontmatter needed for basic commands. ### With YAML Frontmatter Add configuration using YAML frontmatter: ```markdown --- description: Review code for security issues allowed-tools: Read, Grep, Bash(git:*) model: sonnet --- Review this code for security vulnerabilities... ``` ## YAML Frontmatter Fields ### description **Purpose:** Brief description shown in `/help` **Type:** String **Default:** First line of command prompt ```yaml --- description: Review pull request for code quality --- ``` **Best practice:** Clear, actionable description (under 60 characters) ### allowed-tools **Purpose:** Specify which tools command can use **Type:** String or Array **Default:** Inherits from conversation ```yaml --- allowed-tools: Read, Write, Edit, Bash(git:*) --- ``` **Patterns:** - `Read, Write, Edit` - Specific tools - `Bash(git:*)` - Bash with git commands only - `*` - All tools (rarely needed) **Use when:** Command requires specific tool access ### model **Purpose:** Specify model for command execution **Type:** String (sonnet, opus, haiku) **Default:** Inherits from conversation ```yaml --- model: haiku --- ``` **Use cases:** - `haiku` - Fast, simple commands - `sonnet` - Standard workflows - `opus` - Complex analysis ### argument-hint **Purpose:** Document expected arguments for autocomplete **Type:** String **Default:** None ```yaml --- argument-hint: [pr-number] [priority] [assignee] --- ``` **Benefits:** - Helps users understand command arguments - Improves command discovery - Documents command interface ### disable-model-invocation **Purpose:** Prevent SlashCommand tool from programmatically calling command **Type:** Boolean **Default:** false ```yaml --- disable-model-invocation: true --- ``` **Use when:** Command should only be manually invoked ## Dynamic Arguments ### Using $ARGUMENTS Capture all arguments as single string: ```markdown --- description: Fix issue by number argument-hint: [issue-number] --- Fix issue #$ARGUMENTS following our coding standards and best practices. ``` **Usage:** ``` > /fix-issue 123 > /fix-issue 456 ``` **Expands to:** ``` Fix issue #123 following our coding standards... Fix issue #456 following our coding standards... ``` ### Using Positional Arguments Capture individual arguments with `$1`, `$2`, `$3`, etc.: ```markdown --- description: Review PR with priority and assignee argument-hint: [pr-number] [priority] [assignee] --- Review pull request #$1 with priority level $2. After review, assign to $3 for follow-up. ``` **Usage:** ``` > /review-pr 123 high alice ``` **Expands to:** ``` Review pull request #123 with priority level high. After review, assign to alice for follow-up. `
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (1)
Plugin commands have access to `${CLAUDE_PLUGIN_ROOT}`, an environment variable that resolves to the plugin's absolute path.Gates applied: no_behavioural_pass.
29ad4d4206fbfull audit observations/trust-audit/skill/galaxy-dawn__command-development.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 29ad4d4206fb | CAUTION | B | 89 | first audit |
Questions
What does the Command Development skill do?
Semi-automated research assistant for academic research and software development. Supports Claude Code, Codex CLI, Kimi Code CLI, and OpenCode across ideation, coding, experiments, writing, and publication.
Is Command Development safe to install?
With care. The audit graded it B (89/100) and found 1 thing worth knowing before you trust this skill, listed below with the exact line each was found on.
What can Command Development access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Command Development work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (29ad4d4206fb), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.