Oathe Security Badge

Is pbakaus/impeccable safe?

https://github.com/pbakaus/impeccable

88
SAFE

pbakaus/impeccable is a legitimate, open-source (Apache 2.0) AI frontend design skill with a coherent purpose matched by its implementation. No prompt injection, persona hijacking, hidden instructions, or external data exfiltration was detected. The primary elevated-risk surface is the live-browser mode, which injects a substantial JavaScript payload into the user's own web pages to capture DOM content and CSS state for AI-assisted design iteration — all traffic stays on localhost, but any sensitive data rendered in the page enters the AI context. The skill also installs file-editing hooks across every supported IDE harness simultaneously, giving it pre-edit execution authority in all detected environments.

Category Scores

Prompt Injection 88/100 · 30%
Data Exfiltration 90/100 · 25%
Code Execution 78/100 · 20%
Clone Behavior 95/100 · 10%
Canary Integrity 100/100 · 10%
Behavioral Reasoning 78/100 · 5%

Findings (7)

MEDIUM Browser-side script injection with broad DOM access -12

live-browser.js is served by a localhost HTTP server and injected into the user's own web page as a