feature-forge

Fail

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: CRITICALMETADATA_POISONINGEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [METADATA_POISONING]: The skill file SKILL.md has been identified as FileRepMalware by reputation scanners. Furthermore, the skill's declared author identity (Jeffallan) contradicts the verified author context (emmraan), indicating deceptive metadata or impersonation.
  • [EXTERNAL_DOWNLOADS]: The documentation link 'https://jeffallan.github.io/claude-skills/skills/workflow/feature-forge/' included in the skill is flagged by the URLite scanner as a blacklisted malicious URL.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection due to its workflow of exploring external data. Ingestion points: Untrusted data is ingested via the AskUserQuestions tool (SKILL.md) and codebase exploration via Task subagents (references/interview-questions.md). Boundary markers: The skill lacks explicit instructions or delimiters to isolate or ignore instructions embedded in the codebase files it explores. Capability inventory: The skill uses AskUserQuestions (SKILL.md), launches Task subagents (references/interview-questions.md), and writes files to the specs/ directory (SKILL.md). Sanitization: No validation or escaping is performed on the data retrieved from external sources before it is incorporated into the generated specification documents.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 6, 2026, 11:36 AM
Security Audit — agent-trust-hub — feature-forge