proof-writer

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local notes, appendix files, and theorem drafts which may contain untrusted content. It lacks explicit boundary markers or instructions to ignore embedded commands within these files, creating a surface for indirect prompt injection.
  • Ingestion points: Files read during 'Step 1: Gather Proof Context' in SKILL.md, including user-specified paths, local notes, and theorem drafts.
  • Boundary markers: Absent; the instructions do not provide delimiters or 'ignore' warnings to separate external data from the agent's internal logic.
  • Capability inventory: The skill utilizes Read, Write, Edit, Grep, and Glob tools, enabling it to modify the file system based on the processed context.
  • Sanitization: There is no evidence of filtering or escaping of the content read from files before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 06:58 AM
Security Audit — agent-trust-hub — proof-writer