vibe-code-auditor

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is a security-focused utility that identifies common vulnerabilities and technical debt in code. It does not perform network operations, file system modifications, or command execution.
  • [PROMPT_INJECTION]: The skill processes untrusted user-provided source code as its primary input, creating a surface for indirect prompt injection. Ingestion points: User-provided source code snippets or files (SKILL.md). Boundary markers: Absent. Capability inventory: Static textual analysis and report generation. Sanitization: Absent. The risk is considered safe as the skill's capabilities are limited to reporting and it does not execute the input data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 06:57 PM
Security Audit — agent-trust-hub — vibe-code-auditor