What happened?
When a custom command combines @{file} with {{args}} or !{...}, the referenced file content is later re-interpreted as command template syntax instead of remaining static content.
As a result, literal {{args}} inside the referenced file can be replaced with the command arguments, an unterminated !{ can make the whole command fail, and !{...} inside the file can enter the shell approval/execution path.
This appears inconsistent with the documented behavior of @{...} as injecting static reference content. The normal shell permission checks still apply; this is not an approval bypass.
What did you expect to happen?
Content injected through @{...} should be treated as static referenced data and preserved verbatim.
Template syntax inside the referenced file should not be interpreted: literal {{args}} should remain unchanged, !{...} should not be parsed or executed, and malformed template-like text inside the file should not affect the surrounding custom command.
Only syntax originating from the custom command template itself should be processed as template syntax.
Client information
Client Information
Run qwen to enter the interactive CLI, then run the /about command.
$ qwen /about
Qwen Code v0.24.7
Model: deepseek-v4-pro
Fast Model: not set
Auth: openai
Platform: win32 x64 (10.0.26300)
Node.js: v22.23.2
Session: ea611c91-e08d-4924-93d8-d3c5076b4d2c
Git commit: b12edec140
LSP: disabled
Login information
No response
Anything else we need to know?
This appears to be a template-processing/data-boundary bug rather than an approval bypass. I'm happy to work on a fix if maintainers agree that referenced file content should remain literal and with the general direction of preserving its origin through the processor pipeline.
What happened?
When a custom command combines
@{file}with{{args}}or!{...}, the referenced file content is later re-interpreted as command template syntax instead of remaining static content.As a result, literal
{{args}}inside the referenced file can be replaced with the command arguments, an unterminated!{can make the whole command fail, and!{...}inside the file can enter the shell approval/execution path.This appears inconsistent with the documented behavior of
@{...}as injecting static reference content. The normal shell permission checks still apply; this is not an approval bypass.What did you expect to happen?
Content injected through
@{...}should be treated as static referenced data and preserved verbatim.Template syntax inside the referenced file should not be interpreted: literal
{{args}}should remain unchanged,!{...}should not be parsed or executed, and malformed template-like text inside the file should not affect the surrounding custom command.Only syntax originating from the custom command template itself should be processed as template syntax.
Client information
Client Information
Run
qwento enter the interactive CLI, then run the/aboutcommand.Login information
No response
Anything else we need to know?
This appears to be a template-processing/data-boundary bug rather than an approval bypass. I'm happy to work on a fix if maintainers agree that referenced file content should remain literal and with the general direction of preserving its origin through the processor pipeline.