proof-writer

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted local files such as theorem notes and appendix drafts to gather mathematical context. 1. Ingestion points: Workflow Step 1 in SKILL.md identifies that the skill reads local context from user-specified file paths, existing proof drafts, and theorem notes. 2. Boundary markers: The instructions do not define explicit boundary markers or include directives to ignore potential instructions embedded within the ingested files. 3. Capability inventory: The skill has access to file system tools including Read, Write, Edit, Grep, and Glob, but lacks network access, which limits the risk of data exfiltration. 4. Sanitization: The skill does not perform specific sanitization or validation of the content read from files before incorporating it into the proof generation process. Given the primary purpose of the skill is local drafting and the lack of network capabilities, this surface is considered part of the normal operation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 06:51 PM
Security Audit — agent-trust-hub — proof-writer