ai-forge-update

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local Node.js script located at ../ai-forge-create/scripts/validate-metadata.cjs to validate metadata when porting artifacts between platforms.
  • [DATA_EXPOSURE]: Reads and writes local files, including SKILL.md, agent definitions, and evaluation transcripts, to facilitate the update process and persist changes.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests potentially untrusted content from existing artifact files and transcripts. 1. Ingestion points: Reads artifact files and transcripts from the local filesystem. 2. Boundary markers: No technical delimiters are used; the skill relies on a structured phase-based workflow. 3. Capability inventory: Includes file system access (read/write), local shell command execution (Node.js), and tool chaining with other components (ai-forge-apply, ai-forge-judge). 4. Sanitization: Relies on human-in-the-loop verification and paraphrasing of changes before they are applied.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 07:14 AM
Security Audit — agent-trust-hub — ai-forge-update