Config files are parsed line-by-line. The detection of orocos.rb ruby code injection is executed even on line s that are commented.
Commented lines can be filtered either here or here
The issue was originally reported here: https://git.hb.dfki.de/d-rock/cnd-orogen-execution/issues/2