forge

Warn

Audited by Socket on Aug 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The overall workflow is coherent for an end-to-end ticket implementation skill, and most stated integrations are proportionate and routed through official service CLIs. However, the core `scrutiny` executable is introduced via a local bootstrap script with no verifiable provenance in the supplied skill, creating a high install-trust risk; combined with headless auto-commit/PR behavior and prompt-injection exposure from remote ticket content, this makes the skill medium-high risk despite no clear evidence of deliberate malware or explicit credential exfiltration.

Confidence: 83%Severity: 79%
Audit Metadata
Analyzed At
Aug 3, 2026, 02:59 AM
Package URL
pkg:socket/skills-sh/morphet81%2Fscrutiny%2Fforge%2F@784573e4aa2134d85b7cdf305d4dd1cc6d979abe20ab6522771deb86f36b1fb1
Security Audit — socket — forge