vibecoded-design-tells-analysis

Warn

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The instructions require cloning a repository from an unverified GitHub account (JCarterJohnson), which is not associated with the stated author's trusted infrastructure.
  • [COMMAND_EXECUTION]: Setup and usage require executing multiple Python scripts (collect.py, devibe_scan.py, etc.) and installing packages via pip from the unverified repository.
  • [REMOTE_CODE_EXECUTION]: The skill uses urllib.request to communicate with an external API (arctic-shift.photon-reddit.com) to fetch Reddit data.
  • [DATA_EXFILTRATION]: The scanners access and read local files to identify design and code patterns. The execution of unverified scripts with both file-read access and network capabilities constitutes a potential data exfiltration vector.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 22, 2026, 01:20 AM
Security Audit — agent-trust-hub — vibecoded-design-tells-analysis