using-forge
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill uses high-urgency language and mandatory directives ('MUST invoke', 'not negotiable', 'EXTREMELY-IMPORTANT') to override the agent's default decision-making process. It specifically instructs the agent to disregard its own reasoning ('You cannot rationalize your way out of it') and prioritizing the skill's instructions over standard operating procedures.
- [INDIRECT_PROMPT_INJECTION]: The skill serves as a dispatcher for other 'Forge' skills. While it does not ingest untrusted data itself, it creates a surface where subsequent skills (e.g.,
research,review, ordev) will process external codebase content, PR feedback, or web search results without explicit boundary markers or sanitization instructions defined in this kernel skill. - [PROMPT_INJECTION]: The 'Subagent escape hatch' section instructs the agent to delegate tasks to subagents. If a subagent is given a task derived from untrusted input without proper context isolation, it could lead to the propagation of injected instructions across agent boundaries.
Audit Metadata