skillforge
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references source code and installation taps from the author's GitHub repositories (github.com/itamaker/forge-skill, itamaker/tap/skillforge). These are documented as setup resources for the skill utility.
- [COMMAND_EXECUTION]: The instructions direct the agent to build the CLI tool from source using Go and execute its subcommands (draft, init) for file processing and directory scaffolding.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an ingestion surface through the processing of untrusted external data from user-provided Markdown briefs and JSON specifications. 1. Ingestion points: Files provided via the -brief, -catalog, and -spec flags as documented in SKILL.md and references/REFERENCE.md. 2. Boundary markers: The binary uses pattern matching for drafting and structural validation for scaffolding; no specific prompt delimiters are implemented. 3. Capability inventory: The tool performs file system writes in the user-specified output directory using the init subcommand. 4. Sanitization: Validation checks are performed on the JSON schema by the CLI tool to ensure required fields (name, description, tools) are present before writing files.
Audit Metadata