ncode-anti-vibe-coding

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read an external project file named DESIGN.md to enforce specific design tokens. While this introduces a surface for indirect instructions to enter the agent's context, the skill's capabilities are limited to UI/UX styling and code formatting, posing no significant security risk.
  • [OBFUSCATION]: The file references/css-logical-properties.md contains Unicode BiDi control characters (e.g., LRE, RLE, PDF). These are explicitly documented in a reference table for their legitimate technical purpose in handling Right-to-Left (RTL) text and do not constitute malicious obfuscation.
  • [SAFE]: The skill uses instructional language to enforce design quality ('hard-banned', 'instant fails'). This is standard for design system enforcement and does not attempt to bypass core AI safety guardrails.
  • [SAFE]: The skill references standard, well-known UI libraries and fonts such as Tailwind CSS, Lucide, Phosphor Icons, and Google Fonts (Heebo, Rubik). No suspicious or unversioned remote dependencies are introduced.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 07:02 PM