forge
Warn
Audited by Socket on Sep 3, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s core repo-fixing workflow is internally coherent and includes meaningful safety limits, but it expands trust to multiple external services/skills and allows broad autonomous action under automode. Risk comes from transitive tool trust, third-party code/context sharing, and untrusted-content processing with write access, not from clearly malicious behavior.
Confidence: 86%Severity: 61%
Audit Metadata