vibe-code-auditor
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is a security-focused utility that identifies common vulnerabilities and technical debt in code. It does not perform network operations, file system modifications, or command execution.
- [PROMPT_INJECTION]: The skill processes untrusted user-provided source code as its primary input, creating a surface for indirect prompt injection. Ingestion points: User-provided source code snippets or files (SKILL.md). Boundary markers: Absent. Capability inventory: Static textual analysis and report generation. Sanitization: Absent. The risk is considered safe as the skill's capabilities are limited to reporting and it does not execute the input data.
Audit Metadata