Vibe AgentsSAFE
Templates and workflow for generating PRDs, Tech Designs, and MVP and more using LLMs for AI IDEs
Overview
Templates and workflow for generating PRDs, Tech Designs, and MVP and more using LLMs for AI IDEs
844e6869035fOBSERVED · 2026-10-08What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: vibe-agents description: "Create project agent instructions and tool configuration from agreed product and technical decisions." allowed-tools: Read, Write, Edit, Glob, Grep, Bash, AskUserQuestion --- # Project agent instructions Use agreed requirements, technical decisions, and the existing repository to write only stable, non-obvious guidance. For a targeted AGENTS.md edit, update the affected instructions directly; do not require an installer, new PRD, or full interview. Keep progress in the project's memory/handoff file rather than the always-loaded rules. For initial Vibe Workflow setup, use the configured manifest paths. If the vibeworkflow CLI is available, inspect `npx vibeworkflow --dry-run --json` and initialize within the user's authorization. Preserve existing files; replacement flags are for intentional replacements whose affected files have been reviewed. The CLI installs files directly, not into a new templates/ directory. Fill relevant placeholders from known decisions. Keep task-specific procedures in skills or references and load them only when relevant. Distinguish local implementation from external sends, production changes, and new access. Do not enable broad tool permissions just to make setup convenient. Use `npx vibeworkflow doctor` for CLI-generated setup when available; it checks configuration, not a working build or user journey. In a chat without filesystem access, use the repository's docs/context-pack.md and supplied product decisions to produce separated files to save. State absent template/context limitations instead of inventing them. Continue into implementation only when that is part of the user's request.
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
844e6869035ffull audit observations/trust-audit/skill/khazp__vibe-agents.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 844e6869035f | SAFE | B | 89 | first audit |
Questions
What does the Vibe Agents skill do?
Templates and workflow for generating PRDs, Tech Designs, and MVP and more using LLMs for AI IDEs
Is Vibe Agents safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Vibe Agents access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (844e6869035f), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.