feature-forge
Fail
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill includes a documentation link to
https://jeffallan.github.io/claude-skills/skills/workflow/feature-forge/. This domain and specific path are currently blacklisted by automated reputation scanners due to confirmed malicious activity. - [METADATA_POISONING]: The
SKILL.mdfile has a confirmed negative reputation (FileRepMalware), indicating the skill package is associated with known malicious distributions. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user requirements to generate specifications and coordinate subagents, creating a vulnerability to embedded instructions. Ingestion points: User input from
AskUserQuestionsand interview responses inSKILL.md. Boundary markers: Absent; the skill does not use delimiters or instructions to ignore commands within user requirement text. Capability inventory: Usage ofTasksubagents and the ability to write documents to thespecs/directory. Sanitization: No sanitization or validation is applied to user-provided content before it is interpolated into agent instructions or saved to the filesystem.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata