vibes
Pass
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute local bun scripts that manage the editor server and handle application deployment to Cloudflare.
- [EXTERNAL_DOWNLOADS]: The application template loads runtime dependencies including React, TinyBase, Babel, and Tailwind CSS from well-known CDNs such as esm.sh, unpkg.com, and jsdelivr.net.
- [SAFE]: User credentials and API keys are managed through standard practices, using local caching in a dedicated directory (~/.vibes/auth.json) and prompting the user for input, with no signs of malicious exfiltration.
Audit Metadata