vibe-audit-technique

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow where the agent must ingest and analyze the source code of external "vibe-coded" applications which are inherently untrusted.
  • Ingestion points: The agent reads source code, database migrations, and configuration files (e.g., Next.js Server Actions, Supabase RLS policies) from external repositories.
  • Boundary markers: The skill does not provide instructions to the agent on how to differentiate between legitimate code and malicious instructions that might be embedded in comments or documentation within the target repository.
  • Capability inventory: The agent uses file system read capabilities to perform deep source code reviews and logic analysis.
  • Sanitization: No sanitization or filtering logic is provided to ensure that instructions found within the audited code do not override the agent's auditing mission.
  • [SAFE]: The skill provides defensive security guidance, such as SQL Row-Level Security patterns, JWT verification best practices, and secure environment variable management. These are intended to help the agent identify and fix vulnerabilities.
  • [SAFE]: References to external services like Stripe, Supabase, Vercel, and OpenAI are used in a purely technical context to describe common security pitfalls and integration guidelines for modern web stacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — vibe-audit-technique