vibe-coding

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a comprehensive set of guidelines and templates for senior-level software engineering collaboration. It focuses on transparency, craftsmanship, and systematic problem-solving.
  • [SAFE]: A static detection for destructive system commands (rm -rf /) in references/domains/security.md was evaluated and found to be benign. The string appears within an educational context illustrating how command injection vulnerabilities occur, not as an instruction for the agent to execute.
  • [SAFE]: No obfuscation techniques, hidden payloads, or suspicious Base64/Unicode patterns were detected across the skill's files.
  • [SAFE]: The skill explicitly instructs against common security pitfalls, such as hardcoding secrets, skipping input validation, and failing to handle errors gracefully.
  • [SAFE]: There are no attempts to exfiltrate data, perform unauthorized network requests, or establish persistence. The examples provided (e.g., API calls) are standard development templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 01:54 PM
Security Audit — agent-trust-hub — vibe-coding