code-forge

Warn

Audited by Socket on May 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's stated purpose and capabilities mostly align for code generation, and there is no direct credential theft or exfiltration behavior in the text. The main concern is transitive trust: it depends on multiple unspecified helper skills and command-like references without pinned publisher/version, so a resolver could pull different downstream instructions than the user expects. Overall this is a medium-risk orchestration skill rather than confirmed malware.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 26, 2026, 11:05 PM
Package URL
pkg:socket/skills-sh/techygarg%2Flattice%2Fcode-forge%2F@f429f33699a0b53598fbdeeeda96e0308088f081
Security Audit — socket — code-forge