vibe-review
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external code, diffs, and developer instructions, creating a potential surface for indirect prompt injection where malicious instructions could be embedded in the reviewed data.
- Ingestion points: The skill reads proposed changes, instructions, and test results from the project files.
- Boundary markers: No explicit delimiters or instructions to ignore embedded commands within the processed data are present in the skill definition.
- Capability inventory: The skill is configured to use the
Bashtool for command execution andRead,Glob, andGrepfor file system access. - Sanitization: There is no mention of sanitization or validation for the data being processed.
Audit Metadata