vibe-to-speckit-superpowers
Pass
Audited by Gen Agent Trust Hub on Jun 12, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The agent is instructed to invoke various command-line tools (e.g., vibe-browser-audit, runtime-observer) and execute generated discovery scripts and characterization tests using the allowed Bash tool. This activity is integral to the skill's reengineering function.
- [PROMPT_INJECTION]: The skill processes untrusted external data (undocumented prototypes and API traffic) and uses this data to generate executable scripts. This represents an indirect prompt injection surface. However, the risk is mitigated by built-in validators; specifically, Step 2 employs a fixture-portability-validator to identify and remove sensitive information like secrets and local user directories from the output.
Audit Metadata