prove-it
Pass
Audited by Gen Agent Trust Hub on Jul 7, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the Bash tool to execute
git log --oneline -20. This is a standard and safe operation used to identify recent project activity and prioritize relevant questions for the user. - [DATA_EXPOSURE]: The skill systematically explores the project codebase, including configuration files, infrastructure-as-code definitions (Terraform, CloudFormation, CDK), and CI/CD pipelines. While this involves reading high-value architectural data, it is a core requirement of the skill's functionality and the data is processed locally to generate questions without being exfiltrated.
- [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it reads untrusted data from the repository, including instruction files for other agent skills (
.claude/skills/**/SKILL.md). Malicious instructions embedded in these files could potentially influence the agent's behavior during the assessment. - Ingestion points: Scans and reads various project files using Glob, Grep, and Read tools.
- Boundary markers: The instructions do not define delimiters or specific isolation protocols for the content being read from the codebase.
- Capability inventory: The skill uses file system exploration tools and Bash execution capabilities.
- Sanitization: The skill does not perform explicit sanitization or filtering of the content read from files before processing it internally.
Audit Metadata