ph-comment-responder
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [NO_CODE]: The skill consists entirely of Markdown instructions, response templates, and engagement guidelines. No executable scripts, dependencies, or shell commands are included.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external content (Product Hunt comments) to generate responses. This constitutes an untrusted data ingestion surface.
- Ingestion points: The skill explicitly processes an
ORIGINAL COMMENTprovided in the input/output cycle. - Boundary markers: The skill uses clear labels (e.g.,
ORIGINAL COMMENT:,RESPONSE:) to demarcate the untrusted input from the agent's instructions. - Capability inventory: The skill has no capabilities to execute code, access the filesystem, or perform network requests, which significantly limits the impact of any potential injection.
- Sanitization: No explicit sanitization or filtering is defined in the instructions; the skill relies on the LLM's default safety guardrails and human review of the generated response.
Audit Metadata