skills/othmanadi/vibe-skills/vibe/Gen Agent Trust Hub

vibe

Warn

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install a dependency using npx skills add heredotnow/skill, which downloads and runs code from an unverified external source.\n- [COMMAND_EXECUTION]: The skill executes a local shell script located at ~/.agents/skills/here-now/scripts/publish.sh to handle website deployment.\n- [INDIRECT_PROMPT_INJECTION]: The skill generates and reviews HTML and JavaScript code based on user-provided natural language descriptions, creating a surface for potential injection of malicious scripts into the generated website.\n
  • Ingestion points: Natural language descriptions for website generation in SKILL.md.\n
  • Boundary markers: No explicit delimiters or instructions to ignore embedded prompts are defined.\n
  • Capability inventory: The skill writes to the local filesystem (./vibe-output/) and executes deployment scripts (publish.sh).\n
  • Sanitization: No logic is provided to sanitize user-provided text or validate the generated code for security vulnerabilities like XSS.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 28, 2026, 01:14 PM
Security Audit — agent-trust-hub — vibe