Vibe TechdesignSAFE
Templates and workflow for generating PRDs, Tech Designs, and MVP and more using LLMs for AI IDEs
Overview
Templates and workflow for generating PRDs, Tech Designs, and MVP and more using LLMs for AI IDEs
844e6869035fOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned | |
| codex | mentioned | |
| copilot | mentioned | |
| cursor | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: vibe-techdesign description: "Write an MVP technical design from agreed requirements, including architecture choices and relevant tradeoffs." allowed-tools: Read, Write, Glob, Grep, WebSearch, AskUserQuestion --- # MVP technical design Read the agreed requirements and reuse Handoff Context. Inspect an existing project's stack and relevant implementation before proposing replacements. Ask only for consequential choices that remain unresolved; a known answer does not need another confirmation echo. Describe the architecture needed for the core journey: component/service boundaries, data ownership, integration contracts, deployment target, and relevant failure behavior. Prefer the smallest design that meets requirements. Add auth, storage, infrastructure, AI, or paid services only when justified. Verify changing vendor details from the installed code or official sources. Record meaningful tradeoffs, compatibility constraints, migration/recovery requirements where applicable, and how the result will be checked. Distinguish local test operations from external sends, production writes, and deployments. Keep secrets out of generated documents. Do not assign broad tool permissions or require a team of agents to execute an ordinary implementation. Use the manifest's configured design path or `docs/TechDesign-[AppName]-MVP.md`. Quick mode can be a short architecture and implementation plan; deeper modes should expand only where uncertainty or risk warrants it. End with Handoff Context carrying app, known user level, platform, budget, timeline, mode, constraints, decisions, source files, and open questions. Continue to the next authorized workflow stage rather than stopping solely because a document exists. For a guided interview with unresolved requirements, consult the relevant [optional question prompts](references/question-bank.md). When producing a document for `vibeworkflow`, include the exact [CLI output metadata](references/cli-output.md). This is a parser contract, not an optional prose template.
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
844e6869035ffull audit observations/trust-audit/skill/khazp__vibe-techdesign.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 844e6869035f | SAFE | B | 89 | first audit |
Questions
What does the Vibe Techdesign skill do?
Templates and workflow for generating PRDs, Tech Designs, and MVP and more using LLMs for AI IDEs
Is Vibe Techdesign safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Vibe Techdesign access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Vibe Techdesign work with?
Its documentation mentions claude-code, codex, copilot and cursor. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (844e6869035f), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.