skills/cursor/plugins/no-comments/Gen Agent Trust Hub

no-comments

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from user source files and diffs, creating a potential surface for indirect prompt injection via maliciously crafted comments that could influence the sub-agent or refactoring logic.\n- Ingestion points: Reads data from external files, diffs, and the output of the 'Comment Sicko' sub-agent.\n- Boundary markers: Includes logical constraints to reject application-code edits, scope escapes, and unauthorized deletions.\n- Capability inventory: Possesses capabilities to modify files, delete content, spawn tasks, and run architectural tools.\n- Sanitization: Utilizes logical validation rules and requires explicit human approval before encoding constraints or implementing fixes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 07:38 PM
Security Audit — agent-trust-hub — no-comments