feature-forge
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The documentation URL 'https://jeffallan.github.io/claude-skills/skills/workflow/feature-forge/' has been flagged by multiple reputation scanners as malicious (URL:Blacklist). Additionally, the skill's main configuration file 'SKILL.md' has a confirmed malicious reputation detection (FileRepMalware).
- [INDIRECT_PROMPT_INJECTION]: The skill's core workflow involves conducting workshops that ingest untrusted user requirements to generate specifications and drive Task subagents, which constitutes a surface for indirect prompt injection.
- Ingestion points: User input collected via the 'AskUserQuestions' tool during the Discovery and Interview phases as defined in SKILL.md.
- Boundary markers: None. The instructions do not specify delimiters or provide warnings to ignore embedded instructions within user-provided requirement data.
- Capability inventory: File system writing to the 'specs/' directory, execution of the 'AskUserQuestions' tool, and the invocation of Task subagents for architectural and security analysis.
- Sanitization: None. There is no evidence of input validation, filtering, or escaping of user-provided content before it is processed by the agent or subagents.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata