← Home

@vibe-agent-toolkit/vat-development-agents

VAT development agents - dogfooding the vibe-agent-toolkit

29
Versions
MIT
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

jeffrdutton

Keywords

vat-agentvibe-agentagent-bundledevelopment-tools

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/generated/resources/skills/vat-distribution.js AI (source-diff): Same generated-from-markdown pattern; long lines are readable documentation text, not obfuscation. ai
source-diff large-new-source-files AI (source-diff): New files are generated skill bundles from markdown; expected growth pattern for this agent-toolkit package. ai
source-diff obfuscated-file:dist/generated/resources/skills/vat-agent-authoring.js AI (source-diff): Same pattern: generated markdown-to-JS export with long documentation string constants. ai
source-diff obfuscated-file:dist/generated/resources/skills/vat-debugging.js AI (source-diff): Same pattern: generated markdown-to-JS export with long documentation string constants. ai
source-diff obfuscated-file:dist/generated/resources/skills/vat-skills-distribution.js AI (source-diff): Same pattern: generated markdown-to-JS export with long documentation string constants. ai
source-diff obfuscated-file:dist/generated/resources/skills/vat-knowledge-resources.js AI (source-diff): Same pattern: generated markdown bundle with readable documentation content. ai
source-diff obfuscated-file:dist/generated/resources/skills/skill-quality-checklist.js AI (source-diff): Long lines are markdown content embedded as JS string literals via code generation; not obfuscation. ai
source-diff obfuscated-file:dist/generated/resources/skills/vat-claude-org-admin.js AI (source-diff): Same pattern: markdown-to-JS generated export with long string literal; not obfuscation. ai
source-diff obfuscated-file:dist/generated/resources/skills/vat-rag.js AI (source-diff): Generated markdown-to-JS module; long lines are escaped markdown strings, not obfuscation. ai
source-diff obfuscated-file:dist/generated/resources/skills/CLAUDE.js AI (source-diff): Generated markdown-to-JS module; long lines are escaped markdown strings, not obfuscation. ai
source-diff obfuscated-file:dist/generated/resources/skills/vat-adoption-and-configuration.js AI (source-diff): Generated markdown-to-JS module; long lines are escaped markdown strings, not obfuscation. ai
source-diff obfuscated-file:dist/generated/resources/skills/vat-enterprise-org.js AI (source-diff): Generated markdown-to-JS module; long lines are escaped markdown strings, not obfuscation. ai
source-diff obfuscated-file:dist/generated/resources/skills/vat-skill-authoring.js AI (source-diff): Generated markdown-to-JS module; long lines are escaped markdown strings, not obfuscation. ai
source-diff obfuscated-file:dist/generated/resources/skills/vat-skill-distribution.js AI (source-diff): Generated markdown-to-JS module; long lines are escaped markdown strings, not obfuscation. ai
source-diff obfuscated-file:dist/generated/resources/skills/vat-skill-review.js AI (source-diff): Generated markdown-to-JS module; long lines are escaped markdown strings, not obfuscation. ai
source-diff source-size-tripled AI (source-diff): Size increase is due to bundled documentation content, not injected payloads. ai
source-diff obfuscated-file:dist/generated/resources/skills/SKILL.js AI (source-diff): File is a generated JS module exporting a large markdown documentation string, not obfuscated malicious code. ai
install-scripts install-script:postinstall AI (install-scripts): Postinstall invokes the package's own CLI tool with a graceful fallback; consistent with documented plugin install flow. ai
phantom-deps phantom-dep:@vibe-agent-toolkit/agent-schema AI (phantom-deps): Agent-bundle package exports YAML/Markdown; schema dep not imported as JS module by design. ai
phantom-deps phantom-dep:@vibe-agent-toolkit/cli AI (phantom-deps): Same-org CLI dep used at install time via postinstall, not imported as JS module; stable false positive. ai

Versions (showing 29 of 29)

Version Deps Published
0.1.37 3 / 4
0.1.36 3 / 4
0.1.35 3 / 4
0.1.34 3 / 4
0.1.33 3 / 4
0.1.31 3 / 4
0.1.30 3 / 4
0.1.27 3 / 4
0.1.26 3 / 4
0.1.25 3 / 4
0.1.23 3 / 4
0.1.22 3 / 4
0.1.21 3 / 4
0.1.19 2 / 4
0.1.15 2 / 4
0.1.14 2 / 4
0.1.13 2 / 4
0.1.12 2 / 4
0.1.11 2 / 4
0.1.9 2 / 1
0.1.8 2 / 1
0.1.7 2 / 1
0.1.6 2 / 1
0.1.5 2 / 1
0.1.4 2 / 1
0.1.3 2 / 1
0.1.2 2 / 1
0.1.1 2 / 1
0.1.0 2 / 1

v0.1.37

9 findings
HIGH New obfuscated file: dist/generated/resources/skills/CLAUDE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-adoption-and-configuration.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-enterprise-org.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-knowledge-resources.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-rag.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-skill-authoring.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-skill-distribution.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-skill-review.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.36

9 findings
HIGH New obfuscated file: dist/generated/resources/skills/CLAUDE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-adoption-and-configuration.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-enterprise-org.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-knowledge-resources.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-rag.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-skill-authoring.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-skill-distribution.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-skill-review.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.35

8 findings
HIGH New obfuscated file: dist/generated/resources/skills/CLAUDE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-adoption-and-configuration.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-enterprise-org.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-rag.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-skill-authoring.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-skill-distribution.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-skill-review.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.34

8 findings
HIGH New obfuscated file: dist/generated/resources/skills/CLAUDE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-adoption-and-configuration.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-enterprise-org.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-rag.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-skill-authoring.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-skill-distribution.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-skill-review.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.33

8 findings
HIGH New obfuscated file: dist/generated/resources/skills/CLAUDE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-adoption-and-configuration.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-enterprise-org.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-rag.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-skill-authoring.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-skill-distribution.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-skill-review.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.31

3 findings
HIGH New obfuscated file: dist/generated/resources/skills/skill-quality-checklist.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-claude-org-admin.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.30

3 findings
HIGH New obfuscated file: dist/generated/resources/skills/skill-quality-checklist.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-claude-org-admin.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.27

2 findings
HIGH New obfuscated file: dist/generated/resources/skills/vat-claude-org-admin.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.26

2 findings
HIGH New obfuscated file: dist/generated/resources/skills/vat-claude-org-admin.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.25

2 findings
HIGH New obfuscated file: dist/generated/resources/skills/vat-claude-org-admin.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.23

2 findings
HIGH New obfuscated file: dist/generated/resources/skills/vat-claude-org-admin.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.22

2 findings
HIGH New obfuscated file: dist/generated/resources/skills/vat-claude-org-admin.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.21

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: vat claude plugin install --npm-postinstall || exit 0

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.19

5 findings
HIGH New obfuscated file: dist/generated/resources/skills/SKILL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-agent-authoring.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-debugging.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-skills-distribution.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.15

5 findings
HIGH New obfuscated file: dist/generated/resources/skills/SKILL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-agent-authoring.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-debugging.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/generated/resources/skills/vat-distribution.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.14

2 findings
HIGH New obfuscated file: dist/generated/resources/skills/SKILL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.13

2 findings
HIGH New obfuscated file: dist/generated/resources/skills/SKILL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.12

2 findings
HIGH New obfuscated file: dist/generated/resources/skills/SKILL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.11

2 findings
HIGH New obfuscated file: dist/generated/resources/skills/SKILL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.