ph-comment-responder
Pass
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: LOWNO_CODE
Full Analysis
- [NO_CODE] (SAFE): The file 'SKILL.md' contains only prompt-based instructions, guidelines, and response templates. No Python, JavaScript, or shell scripts are present for execution.- [DATA_EXPOSURE] (SAFE): No sensitive information, hardcoded credentials, or private file paths were detected in the content.- [INDIRECT_PROMPT_INJECTION] (INFO): The skill is designed to ingest and process untrusted external data (Product Hunt comments). While this presents a surface for indirect prompt injection, the skill lacks any 'active' capabilities (such as file-writing, network requests, or system command execution) that could be exploited to cause harm. The risk is limited to the generated text output itself.
Audit Metadata