vibe-plan-review

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes implementation plans and requirement specifications which are untrusted external data sources. * Ingestion points: Target implementation plan and requirements specification files identified in SKILL.md. * Boundary markers: The skill does not explicitly utilize delimiters or 'ignore embedded instructions' markers when reading these files. * Capability inventory: The skill has the capability to read files from the workspace and write to both a temporary review file (..review.md) and the original implementation plan file upon user confirmation (SKILL.md). * Sanitization: While the skill features a comprehensive 'Sensitive Content Handling' section to redact credentials and tokens, it does not implement specific sanitization to prevent the agent from obeying instructions embedded within the implementation plans it reviews.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 02:38 PM
Security Audit — agent-trust-hub — vibe-plan-review