vibe-reengineer
Pass
Audited by Gen Agent Trust Hub on Jun 12, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: Indirect prompt injection surface via codebase ingestion. The skill processes untrusted prototype source files and runtime application data to inform its automated refactoring workflow. Ingestion points include project source code, local server state, and business requirements files. Boundary markers are established through a quantitative 'Migration Risk Score' (1-25) and a 'Canonical Truth Hierarchy' that prioritizes verified specifications over inferred code behavior. Capability inventory consists of the Bash, Read, and Write tools for project scaffolding and code modification. Sanitization is implemented via a 'Fixture Portability Validator' designed to scrub authentication tokens, absolute paths, and dynamic identifiers from captured behavioral data.
- [SAFE]: Exceptional safety guardrails and policy enforcement. The skill implements a 'Step 0 Absolute Safety Pre-Check' and an 'AUTONOMOUS_REWRITE_FORBIDDEN' protocol that strictly prevents the agent from refactoring high-risk modules such as authentication, financial billing, cryptography, and regulatory compliance logging. These controls ensure that the autonomous capabilities are limited to non-critical domain logic and architectural structure.
Audit Metadata