vibecoded-design-tells-analysis
Warn
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The instructions require cloning a repository from an unverified GitHub account (JCarterJohnson), which is not associated with the stated author's trusted infrastructure.
- [COMMAND_EXECUTION]: Setup and usage require executing multiple Python scripts (collect.py, devibe_scan.py, etc.) and installing packages via pip from the unverified repository.
- [REMOTE_CODE_EXECUTION]: The skill uses urllib.request to communicate with an external API (arctic-shift.photon-reddit.com) to fetch Reddit data.
- [DATA_EXFILTRATION]: The scanners access and read local files to identify design and code patterns. The execution of unverified scripts with both file-read access and network capabilities constitutes a potential data exfiltration vector.
Audit Metadata