vibecoder-guide
Pass
Audited by Gen Agent Trust Hub on May 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill is primarily composed of instructional text and interaction templates.
- [PROMPT_INJECTION]: The skill provides phrases for user interaction but does not contain instructions to override safety guidelines, bypass constraints, or extract system prompts. An indirect injection surface is noted as the skill analyzes project state files, but its restricted 'Read' capability and purely instructional nature mitigate risk. 1. Ingestion points: Reads AGENTS.md and Plans.md to determine project status. 2. Boundary markers: Absent. 3. Capability inventory: Limited to the 'Read' tool. 4. Sanitization: Absent.
- [DATA_EXFILTRATION]: No network operations or access to sensitive credentials, environment variables, or SSH keys were found.
- [REMOTE_CODE_EXECUTION]: The skill does not download external scripts, install packages, or use dynamic execution functions like eval() or exec().
Audit Metadata