vibe-brainstorm — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited vibe-brainstorm (Agent Skill) and scored it 91/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 1 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} is the classic direct prompt-injection phrasing. Placed in a skill body that the agent reads as trusted instructions, it tries to make the agent abandon its prior rules and follow whatever comes next — a full system-prompt override.
ignore/disregard/forget … previous instructions sentence.Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use this skill before creative implementation scope hardens. It helps agents surface implicit expected behavior, explore Practical / Unconventional / Challenging idea directions, and select a direction without moving it into implementation until the user confirms it.
This is not a hidden single-agent brainstorming prompt. When a mode requires delegation, use real sub-agents only after the host exposes verified delegation capability and the current task authorizes it.
Use this skill when:
vibe-brainstorm or asks for creativeimplementation brainstorming.
interaction rules, UX flow, or implementation direction where implicit expected behavior matters.
expectations, spatial or stateful behavior, UI interaction norms, fairness rules, accessibility expectations, data consistency, or feedback semantics.
Do not use this skill for:
fixes with a concrete plan, or one-line requested changes.
only wants execution.
debug workflow instead.
Brainstormed directions become requirements only after the user confirms them and a requirements-capture workflow records them.
| Situation | Mode |
|---|---|
User explicitly asks for diverge or "ideas only" | diverge |
| Autonomous trigger during implementation work | conventions |
| User asks for convention/expected-behavior checking only | conventions |
User explicitly asks for full, "brainstorm and choose", or a complete creative pass | full |
Explicit vibe-brainstorm invocation with no mode and a creative implementation goal | full |
full is not the autonomous default. Use it autonomously only when the task is clearly creative enough that idea generation, convention grounding, development, and selection are all necessary before implementation can be scoped.
Before running any mode or stage that requires sub-agents:
sub-agents ran. The evidence must be independently captured by the host or runner and visible to the later reader or grader in the current output set, an attached run artifact, delegated invocation metadata, task IDs emitted by the tool system, or an equivalent host record. Assistant-authored prose in the final response is not such evidence.
observable checks, not private chain-of-thought.
stage, state that limitation and stop, or ask whether the user wants a clearly degraded single-agent fallback.
claim sub-agents ran.
A delegation mechanism may be ad-hoc per-role sub-agent invocation or one scripted orchestration run: a host mechanism that fans out several roles under a single deterministic, independently recorded run and returns their results. Both satisfy check 1, and an orchestration run's host-recorded run identity, per-role task records, or run journal satisfies check 3 when the later reader can inspect it. A scripted run cannot pause for user input, so schedule only generator, critic, development, grounding, and selection stages inside it; checklist confirmation and final direction confirmation stay in the conversation after the run returns. Ask each role for a bounded structured result — candidates, fit, tradeoffs, risks, or checklist entries — so results can be collected and merged without re-deriving them. Do not require a specific host orchestration tool.
Any claim that real sub-agents ran must be backed by recordable host-provided evidence. A polished response, role headings, prose-only agent IDs, self-reported token summaries, runtime summaries, or persona-separated sections are not proof of delegation. Do not promote IDs, token totals, runtimes, or references to "above" tool calls that you type into the final response to confirmed; they remain assistant-authored claims unless they cite an independently recorded host artifact, metadata field, host-rendered tool block, task ID, or trace excerpt that the later reader can inspect. If real tool calls happened but the recorded output set is only the final text response, label the delegation claim unproven and keep any single-agent result separate from confirmed delegated output.
When delegation is verified and authorized, use real sub-agents for these roles:
Practical generator.Unconventional generator.Challenging generator.references.
If any role required by the selected mode cannot run, follow the Delegation Gate instead of silently collapsing that role into the coordinator.
divergeUse for idea generation only.
Practical: low-risk ideas that fit familiar expectations.Unconventional: unusual ideas that may reframe the experience.Challenging: ambitious ideas that stretch implementation or interactionassumptions while still targeting the user's goal.
selection, ranking, or adoption recommendation unless the user asks for it.
conventionsUse for expected-behavior grounding without idea generation. This is the default mode when the skill triggers autonomously during implementation work.
delegation is available. Ask what a reasonable user would expect to happen, including edge cases.
missed;
domain references when they are available and relevant. If reference access is missing, label the gap instead of fabricating certainty.
state that limitation before using a single-agent checklist and ask whether the user accepts the degraded checklist as enough to continue. Do not present that fallback as a completed delegated conventions pass.
checklist when it changes behavior, UX, domain rules, or implementation scope.
fullUse for the complete creative pass.
diverge to produce Practical / Unconventional / Challengingcandidates.
conventions grounding pass.delegation is available. Expand the candidate's user experience, implementation shape, risks, and convention interactions.
and domain references.
the violated gate for every rejection.
practicality. Do not reject an unusual candidate merely because it is unusual.
before it becomes implementation scope or is handed to another workflow.
Use all four grounding mechanisms when the mode includes conventions:
cases.
when sub-agents are available.
docs, upstream references, or domain material when relevant and accessible.
checklist affects behavior or scope.
Keep mandatory gates narrow. A gate is mandatory only when missing it would violate the user's goal, a domain convention, accessibility/safety expectation, data contract, or a clear "normal users would expect this" behavior. Put taste, polish, and speculative enhancements outside the mandatory gate.
Anchor convention checks in the current task, supplied references, local code, and the user's stated domain. Do not carry preloaded niche examples, third-party domain rules, platform rules, or fixture-specific checklists into unrelated tasks.
Prefer chat output. Create files only when the user explicitly asks for an artifact.
Use this shape, omitting or marking skipped sections only when the selected mode does not run that stage:
confirmed only when the output set includes independently recorded host/runner evidence and the response cites its artifact, field, tool block, task ID, or trace location; unproven when real calls may have happened but only assistant-authored final text can record them; or unavailable/degraded with the limitation and authorization status.
skipped by mode for diverge.
Practical / Unconventional / Challenging foridea modes, or not generated in conventions mode.
candidates, and adoption recommendation, or skipped by mode.
user must confirm before implementation starts.
Do not include private chain-of-thought from any agent. Summarize conclusions, evidence, tradeoffs, and open questions.
This skill stops at confirmed direction. After user confirmation, hand the confirmed checklist or selected candidate to implementation planning, plan execution, or ordinary coding as appropriate. Without that confirmation, do not start implementation, create code, stage files, commit, or claim the direction is approved.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.