prove-it

Warn

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: MEDIUMINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to treat local files at specific paths (.claude/skills/prove-it/ or .agents/skills/prove-it/) as authoritative, effectively allowing untrusted repository content to override the global skill's instructions. This presents a significant hijacking risk.
  • Ingestion points: Path-based discovery of local skill definitions in the working directory.
  • Boundary markers: None; the instructions explicitly command the agent to "follow it instead."
  • Capability inventory: File system read/write, shell command execution (Step 1, 2, 4), and environment variable access.
  • Sanitization: None; the redirection is unconditional if the file exists.
  • [COMMAND_EXECUTION]: The skill commands the agent to discover and run arbitrary scripts from the repository (e.g., <typecheck cmd>, <build cmd>, and <test file>). In a compromised or malicious repository, these commands could execute harmful payloads with the user's local privileges.
  • [DATA_EXFILTRATION]: While not explicitly sending data to a third party, the skill is instructed to read sensitive CI workflows (.github/workflows/) and environment files (.env) to configure database tests. This combined with the hijacking vector in Step 0 creates a potential path for data access and subsequent exfiltration if the local override is malicious.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 24, 2026, 11:18 PM
Security Audit — agent-trust-hub — prove-it