skill-forge

Warn

Audited by Socket on Jun 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's stated purpose matches a meta-skill that researches and writes new skills, but its footprint is broad and risky for that role. The main concern is indirect prompt injection and persistent propagation of untrusted external content into future auto-loaded skills, plus transitive trust in subagents/other skills. No direct credential harvesting, malicious exfiltration, or unverified binary installer was found.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 13, 2026, 02:33 PM
Package URL
pkg:socket/skills-sh/bm629%2Fagent-skills%2Fskill-forge%2F@bb9f5b48bec4d0f6d852c1fcda0ccb4d95c069a8623b43b8d96c08027616d2fc
Security Audit — socket — skill-forge