prove-it

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is a reasoning framework for fact-checking and does not contain any malicious instructions, unauthorized network exfiltration, or hardcoded credentials.\n- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill processes external claims which could contain adversarial content.\n
  • Ingestion points: Claims provided as skill arguments or retrieved from the conversation history (SKILL.md).\n
  • Boundary markers: Absent. No specific delimiters are mandated to wrap the claim during the verification process.\n
  • Capability inventory: The skill instructs the agent to "Run the command" or "read the file" to verify empirical claims (SKILL.md, Step 3).\n
  • Sanitization: Absent. There are no instructions to validate or escape the claim content before it is used to drive tool execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 06:31 AM
Security Audit — agent-trust-hub — prove-it