skills/irpsv/ai-bro/bro-vibe-code/Gen Agent Trust Hub

bro-vibe-code

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's design focuses on "immediate implementation" and explicitly instructs the agent to avoid showing technical plans, diffs, or internal steps to the user. This reduction in transparency and oversight increases the risk that malicious instructions embedded in the project code or user conversation could be executed autonomously.
  • Ingestion points: The skill collects context from both user conversation and repository files during the context gathering phase.
  • Boundary markers: The subagent prompt templates (e.g., developer-prompt.md) interpolate internal tasks using simple placeholders without structural delimiters or instructions to ignore embedded commands.
  • Capability inventory: The skill utilizes a developer subagent that is expected to modify the repository, create files, and execute tests or linters.
  • Sanitization: No mechanisms for sanitizing, filtering, or validating external inputs are defined in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 06:58 AM
Security Audit — agent-trust-hub — bro-vibe-code