skills/wenjunduan/rlues/vibe-dev/Gen Agent Trust Hub

vibe-dev

Pass

Audited by Gen Agent Trust Hub on May 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes dynamic context injection to run the command 'cat .ai_state/project.json' at load time. This command retrieves internal project state information into the agent's context.
  • [PROMPT_INJECTION]: The skill ingests untrusted user requirements through the $ARGUMENTS variable and passes them into a multi-step development process. 1. Ingestion points: The user requirement description in SKILL.md. 2. Boundary markers: No delimiters or boundary instructions are present to isolate user input from the skill's instructions. 3. Capability inventory: The skill can execute shell commands through dynamic context and triggers external development skills. 4. Sanitization: No sanitization or validation of the input string is observed.
Audit Metadata
Risk Level
SAFE
Analyzed
May 2, 2026, 10:37 PM