feature-forge

Fail

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill includes a documentation link to https://jeffallan.github.io/claude-skills/skills/workflow/feature-forge/. This domain and specific path are currently blacklisted by automated reputation scanners due to confirmed malicious activity.
  • [METADATA_POISONING]: The SKILL.md file has a confirmed negative reputation (FileRepMalware), indicating the skill package is associated with known malicious distributions.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user requirements to generate specifications and coordinate subagents, creating a vulnerability to embedded instructions. Ingestion points: User input from AskUserQuestions and interview responses in SKILL.md. Boundary markers: Absent; the skill does not use delimiters or instructions to ignore commands within user requirement text. Capability inventory: Usage of Task subagents and the ability to write documents to the specs/ directory. Sanitization: No sanitization or validation is applied to user-provided content before it is interpolated into agent instructions or saved to the filesystem.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 5, 2026, 11:38 AM
Security Audit — agent-trust-hub — feature-forge