Is pbakaus/impeccable safe?
https://github.com/pbakaus/impeccable
pbakaus/impeccable is a legitimate, open-source (Apache 2.0) AI frontend design skill with a coherent purpose matched by its implementation. No prompt injection, persona hijacking, hidden instructions, or external data exfiltration was detected. The primary elevated-risk surface is the live-browser mode, which injects a substantial JavaScript payload into the user's own web pages to capture DOM content and CSS state for AI-assisted design iteration — all traffic stays on localhost, but any sensitive data rendered in the page enters the AI context. The skill also installs file-editing hooks across every supported IDE harness simultaneously, giving it pre-edit execution authority in all detected environments.
Category Scores
Findings (7)
MEDIUM Browser-side script injection with broad DOM access -12 ▶
live-browser.js is served by a localhost HTTP server and injected into the user's own web page as a