vibe-matcher

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input (descriptive mood words and brand keywords) which it then writes to files using the Write tool to create visual design specifications. These files are subsequently read by a validation script.\n
  • Ingestion points: Descriptive vibe words and audience details provided by the user in SKILL.md.\n
  • Boundary markers: No explicit delimiters or instructions are provided to ensure the agent ignores embedded instructions within user-provided descriptions.\n
  • Capability inventory: The skill allows Read and Write tool access and involves the execution of a bash script (scripts/validate_visual_dna.sh) that parses JSON data.\n
  • Sanitization: The provided validation script checks for technical field presence and hex code formats but does not validate or sanitize the textual content of design rationales, which could contain injected instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 12:44 PM
Security Audit — agent-trust-hub — vibe-matcher