@vibe-agent-toolkit/vat-development-agents
VAT development agents - dogfooding the vibe-agent-toolkit
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/generated/resources/skills/vat-distribution.js | AI (source-diff): Same generated-from-markdown pattern; long lines are readable documentation text, not obfuscation. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New files are generated skill bundles from markdown; expected growth pattern for this agent-toolkit package. | ai | |
| source-diff | obfuscated-file:dist/generated/resources/skills/vat-agent-authoring.js | AI (source-diff): Same pattern: generated markdown-to-JS export with long documentation string constants. | ai | |
| source-diff | obfuscated-file:dist/generated/resources/skills/vat-debugging.js | AI (source-diff): Same pattern: generated markdown-to-JS export with long documentation string constants. | ai | |
| source-diff | obfuscated-file:dist/generated/resources/skills/vat-skills-distribution.js | AI (source-diff): Same pattern: generated markdown-to-JS export with long documentation string constants. | ai | |
| source-diff | obfuscated-file:dist/generated/resources/skills/vat-knowledge-resources.js | AI (source-diff): Same pattern: generated markdown bundle with readable documentation content. | ai | |
| source-diff | obfuscated-file:dist/generated/resources/skills/skill-quality-checklist.js | AI (source-diff): Long lines are markdown content embedded as JS string literals via code generation; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/generated/resources/skills/vat-claude-org-admin.js | AI (source-diff): Same pattern: markdown-to-JS generated export with long string literal; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/generated/resources/skills/vat-rag.js | AI (source-diff): Generated markdown-to-JS module; long lines are escaped markdown strings, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/generated/resources/skills/CLAUDE.js | AI (source-diff): Generated markdown-to-JS module; long lines are escaped markdown strings, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/generated/resources/skills/vat-adoption-and-configuration.js | AI (source-diff): Generated markdown-to-JS module; long lines are escaped markdown strings, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/generated/resources/skills/vat-enterprise-org.js | AI (source-diff): Generated markdown-to-JS module; long lines are escaped markdown strings, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/generated/resources/skills/vat-skill-authoring.js | AI (source-diff): Generated markdown-to-JS module; long lines are escaped markdown strings, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/generated/resources/skills/vat-skill-distribution.js | AI (source-diff): Generated markdown-to-JS module; long lines are escaped markdown strings, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/generated/resources/skills/vat-skill-review.js | AI (source-diff): Generated markdown-to-JS module; long lines are escaped markdown strings, not obfuscation. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase is due to bundled documentation content, not injected payloads. | ai | |
| source-diff | obfuscated-file:dist/generated/resources/skills/SKILL.js | AI (source-diff): File is a generated JS module exporting a large markdown documentation string, not obfuscated malicious code. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Postinstall invokes the package's own CLI tool with a graceful fallback; consistent with documented plugin install flow. | ai | |
| phantom-deps | phantom-dep:@vibe-agent-toolkit/agent-schema | AI (phantom-deps): Agent-bundle package exports YAML/Markdown; schema dep not imported as JS module by design. | ai | |
| phantom-deps | phantom-dep:@vibe-agent-toolkit/cli | AI (phantom-deps): Same-org CLI dep used at install time via postinstall, not imported as JS module; stable false positive. | ai |
Versions (showing 29 of 29)
| Version | Deps | Published |
|---|---|---|
| 0.1.37 | 3 / 4 | |
| 0.1.36 | 3 / 4 | |
| 0.1.35 | 3 / 4 | |
| 0.1.34 | 3 / 4 | |
| 0.1.33 | 3 / 4 | |
| 0.1.31 | 3 / 4 | |
| 0.1.30 | 3 / 4 | |
| 0.1.27 | 3 / 4 | |
| 0.1.26 | 3 / 4 | |
| 0.1.25 | 3 / 4 | |
| 0.1.23 | 3 / 4 | |
| 0.1.22 | 3 / 4 | |
| 0.1.21 | 3 / 4 | |
| 0.1.19 | 2 / 4 | |
| 0.1.15 | 2 / 4 | |
| 0.1.14 | 2 / 4 | |
| 0.1.13 | 2 / 4 | |
| 0.1.12 | 2 / 4 | |
| 0.1.11 | 2 / 4 | |
| 0.1.9 | 2 / 1 | |
| 0.1.8 | 2 / 1 | |
| 0.1.7 | 2 / 1 | |
| 0.1.6 | 2 / 1 | |
| 0.1.5 | 2 / 1 | |
| 0.1.4 | 2 / 1 | |
| 0.1.3 | 2 / 1 | |
| 0.1.2 | 2 / 1 | |
| 0.1.1 | 2 / 1 | |
| 0.1.0 | 2 / 1 |
v0.1.37
9 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.36
9 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.35
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.34
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.33
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.31
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.30
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.27
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.26
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.25
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.23
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.22
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.21
2 findingsScript: vat claude plugin install --npm-postinstall || exit 0
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.19
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.15
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.14
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.13
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.12
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.11
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.