vibe-spec-packager
Pass
Audited by Gen Agent Trust Hub on Jun 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates entirely within the local project scope, reading specification documents and writing directory structures and markdown files. No high-risk behaviors or security vulnerabilities were identified.
- [COMMAND_EXECUTION]: The skill utilizes the Bash tool for routine project initialization tasks, such as creating directory trees and copying local domain artifacts. These operations are restricted to the project's target directories and follow standard development workflows.
- [DATA_EXFILTRATION]: There is no evidence of network-enabled tools or instructions that attempt to move data to external domains. The skill lacks network permissions and targets local file paths.
- [PROMPT_INJECTION]: The instructions establish a professional DevOps persona without attempting to bypass safety filters, extract system prompts, or override core agent guidelines.
Audit Metadata