comment-mode
Pass
Audited by Gen Agent Trust Hub on Apr 10, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill writes feedback to a local HTML file and opens it using the
opencommand. This is a standard functionality for displaying generated previews to the user. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided drafts which acts as an ingestion point for untrusted data. 1. Ingestion points: User-provided text drafts described in the feedback workflow. 2. Boundary markers: Absent in the interpolation template. 3. Capability inventory: File-write to
_private/views/andopensubprocess (SKILL.md). 4. Sanitization: The template's JavaScript usestextContentfor rendering comments, providing protection against XSS in the comment text itself, though the primary draft content is interpolated into the HTML body.
Audit Metadata