ph-comment-responder

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill consists entirely of Markdown instructions, response templates, and engagement guidelines. No executable scripts, dependencies, or shell commands are included.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external content (Product Hunt comments) to generate responses. This constitutes an untrusted data ingestion surface.
  • Ingestion points: The skill explicitly processes an ORIGINAL COMMENT provided in the input/output cycle.
  • Boundary markers: The skill uses clear labels (e.g., ORIGINAL COMMENT:, RESPONSE:) to demarcate the untrusted input from the agent's instructions.
  • Capability inventory: The skill has no capabilities to execute code, access the filesystem, or perform network requests, which significantly limits the impact of any potential injection.
  • Sanitization: No explicit sanitization or filtering is defined in the instructions; the skill relies on the LLM's default safety guardrails and human review of the generated response.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:25 PM
Security Audit — agent-trust-hub — ph-comment-responder