specforge-close
Pass
Audited by Gen Agent Trust Hub on May 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes Node.js to run several scripts located in the local
.specforge/tools/directory, includingcreate-artifact.mjs,gate.mjs,doctor.mjs, andarchive-change.mjs. These scripts are intended for internal project maintenance and artifact generation. - [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it processes external documentation to update the project SSoT. 1. Ingestion points:
.specforge/project/and.specforge/rules/directories. 2. Boundary markers: Absent. 3. Capability inventory: Local script execution and file archiving. 4. Sanitization: Absent. This surface is inherent to the skill's purpose of knowledge synchronization.
Audit Metadata