prove-it
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes development commands (e.g.,
dev,preview) and networking tools likecurlto verify the state of a project. It limits these operations to existing repository commands and requires user confirmation before running custom scripts. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from web pages and API responses, which could potentially contain malicious instructions intended to influence the agent's behavior.
- Ingestion points: Browser navigation and interaction in Procedure 2, and command outputs from
curlor scripts in Procedure 3. - Boundary markers: No explicit delimiters or instructions are provided to the agent to distinguish between its instructions and the data retrieved from external sources.
- Capability inventory: The skill has the ability to execute shell commands and write markdown reports to the local
.agent/scratch/directory. - Sanitization: There is no mention of sanitizing or escaping the data fetched from external URLs or API endpoints.
- [DYNAMIC_EXECUTION]: The skill allows the agent to generate and run example applications or small scripts to verify API changes at runtime. Although this presents a risk, the skill explicitly mandates user consent for file placement and the addition of any new packages or dependencies.
Audit Metadata