skills/gannonh/skills/ps-no-comments/Gen Agent Trust Hub

ps-no-comments

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The references/comment-sicko.md file utilizes a strong role-play persona ('Comment Sicko') characterized by aggressive language ('deranged comment-hater', 'Yes... Ha ha ha... Yes!', 'Kill them'). While designed to maintain task focus on code cleanup, this style of instruction mimics patterns often used to override or bias agent safety filters and operational constraints.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and acts upon user-provided code files and diffs. Because the agent evaluates the content of comments to determine refactoring paths or deletion eligibility, it is susceptible to malicious instructions hidden within those comments that could attempt to influence the agent's code-writing or tool-calling behavior.
  • Ingestion points: Reads files or repository diffs as defined in the scope of SKILL.md.
  • Boundary markers: There are no explicit markers or instructions telling the agent to treat comment content as untrusted data or to ignore executable-style instructions within them.
  • Capability inventory: The skill can modify application code, delete file content, spawn subagents, and call external investigative tools such as ps-architect, ps-how, and ps-why.
  • Sanitization: The skill does not implement validation or sanitization of the comment text before the LLM processes it and proposes code modifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 01:26 AM
Security Audit — agent-trust-hub — ps-no-comments