proof-checker
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted LaTeX proof files provided by the user, which presents a surface for indirect prompt injection where instructions could be hidden in comments or complex math structures.
- Ingestion points: The skill reads
.texfiles and reference materials from the user's project directory. - Boundary markers: The skill uses delimiters such as
[FULL PROOF CONTENT HERE]and[FIXED SECTION ONLY]in its prompts to the reviewer models, which provides basic separation but may not prevent sophisticated injection. - Capability inventory: The agent has extensive capabilities including
Bashfor command execution,Edit/Writefor file modification,Agentfor spawning sub-agents, and several MCP tools for external model interaction. - Sanitization: There is no evidence of sanitization or filtering of the LaTeX source code before it is passed to the models for reasoning.
- [COMMAND_EXECUTION]: The skill executes shell commands via the
Bashtool to compile LaTeX documents and run a local Python script for wiki management. - Evidence: The skill calls
pdflatex -interaction=nonstopmode <file>.texin Phase 2e andpython3 "$WIKI_SCRIPT" add_claim ...in Phase 5.5.
Audit Metadata