prove-it-works
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to read external artifacts including git diffs and file contents, creating a surface for potential indirect prompt injection from those files. \n- Ingestion points:
SKILL.mdinstructions to inspect "git diff, file contents, runtime behavior". \n- Boundary markers: Delimiters or instructions to ignore embedded content are not specified. \n- Capability inventory: The skill mentions building code, running features, and executing scripts. \n- Sanitization: No content validation or sanitization is described. \n- [DYNAMIC_EXECUTION]: The skill promotes generating and running scripts to verify work, which is a standard procedure in software development but involves dynamic code generation. \n- Evidence:SKILL.mdincludes the instruction to "Write the script, run it, and keep its output as an artifact."
Audit Metadata