prune-comments
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes source code files from the repository which are considered untrusted input. Maliciously crafted comments within these files could attempt to influence the agent's logic or behavior during the pruning process.
- Ingestion points: The skill reads local source files, scripts, and configuration files as defined in the scope section of
SKILL.md. - Boundary markers: The skill does not implement specific boundary markers or 'ignore' instructions for the content of the files being read.
- Capability inventory: The skill has the capability to read files and write modifications back to the file system (specifically pruning comments).
- Sanitization: The skill relies on a strict taxonomy and the exclusion of semantic directives to filter content, but does not perform technical sanitization of comment strings.
- [COMMAND_EXECUTION]: The skill instructions involve executing standard command-line utilities including
git,cloc,scc, andtokeito perform diffs and calculate code metrics. These tools are assumed to be pre-installed in the execution environment.
Audit Metadata