forge-ship
Warn
Audited by Socket on May 5, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's capabilities mostly match its software-delivery purpose, but risk comes from autonomous unattended actions and the broader transitive trust model for installing a personal-repo skill via the `skills` CLI. No direct credential harvesting, exfiltration endpoint, or off-purpose behavior is visible in this fragment.
Confidence: 81%Severity: 57%
Audit Metadata