skills/go7hic/ystack/no-comments/Gen Agent Trust Hub

no-comments

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: Technical analysis of the skill's instructions and referenced runtime documentation confirms that its operations are confined to local code maintenance. No evidence of malicious behavior, such as credential harvesting, unauthorized network access, or persistence mechanisms, was found.
  • [COMMAND_EXECUTION]: The skill references the use of helper tools and sub-commands like /architect, /how, and /why. These are standard functional extensions within the agent's development environment used for code analysis and restructuring, and do not involve the execution of arbitrary or dangerous system commands.
  • [PROMPT_INJECTION]: The skill uses specialized instructional language, such as referring to a 'Comment Sicko' rubric and directing the agent to adopt a 'fresh perspective'. These are task-oriented role-play instructions that guide the agent's auditing logic and do not attempt to override core safety protocols or bypass constraints.
  • [SAFE]: The skill processes user-provided source code and git diffs to perform its tasks. This represents an indirect prompt injection surface; however, the skill's logic is specifically designed to evaluate and override instructions found in comments (e.g., 'do not remove'), which mitigates common risks associated with processing untrusted data.
  • Ingestion points: Local source files and diffs against the base branch (SKILL.md).
  • Boundary markers: Absent; the agent relies on its understanding of code syntax to identify comments.
  • Capability inventory: File modification, code deletion, and delegation to specialized local sub-agents (SKILL.md).
  • Sanitization: None; the skill relies on the agent's inherent capability to interpret and safely handle code content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 03:07 PM
Security Audit — agent-trust-hub — no-comments