forge
Warn
Audited by Socket on Aug 3, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The overall workflow is coherent for an end-to-end ticket implementation skill, and most stated integrations are proportionate and routed through official service CLIs. However, the core `scrutiny` executable is introduced via a local bootstrap script with no verifiable provenance in the supplied skill, creating a high install-trust risk; combined with headless auto-commit/PR behavior and prompt-injection exposure from remote ticket content, this makes the skill medium-high risk despite no clear evidence of deliberate malware or explicit credential exfiltration.
Confidence: 83%Severity: 79%
Audit Metadata