ncode-anti-vibe-coding
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read an external project file named
DESIGN.mdto enforce specific design tokens. While this introduces a surface for indirect instructions to enter the agent's context, the skill's capabilities are limited to UI/UX styling and code formatting, posing no significant security risk. - [OBFUSCATION]: The file
references/css-logical-properties.mdcontains Unicode BiDi control characters (e.g., LRE, RLE, PDF). These are explicitly documented in a reference table for their legitimate technical purpose in handling Right-to-Left (RTL) text and do not constitute malicious obfuscation. - [SAFE]: The skill uses instructional language to enforce design quality ('hard-banned', 'instant fails'). This is standard for design system enforcement and does not attempt to bypass core AI safety guardrails.
- [SAFE]: The skill references standard, well-known UI libraries and fonts such as Tailwind CSS, Lucide, Phosphor Icons, and Google Fonts (Heebo, Rubik). No suspicious or unversioned remote dependencies are introduced.
Audit Metadata