rescue-vibe-project

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and repair "brittle existing projects," which serves as an ingestion point for untrusted data. 1. Ingestion points: Project assets including code, tests, schemas, and migrations as described in SKILL.md. 2. Boundary markers: The instructions do not specify the use of delimiters or "ignore" markers when processing external project content. 3. Capability inventory: The skill instructs the agent to invoke other skills (e.g., debug-with-evidence, safe-change) to perform analysis and repair tasks. 4. Sanitization: No specific data sanitization or filtering logic is defined for the ingested project content, although the triage phase explicitly includes a check for security and secrets.
  • [SAFE]: The skill instructions define a process for project recovery and repair. No malicious patterns, such as command execution, data exfiltration, or obfuscation, were identified. The methodology explicitly includes security and secrets triage as high-priority tasks, which aligns with security best practices when handling legacy codebases.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 05:54 AM
Security Audit — agent-trust-hub — rescue-vibe-project