forge-analytics

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes vendor-specific CLI tools such as forge and fullstack-forge to perform automated audits. It includes a specific security safeguard instructing the agent to never execute fetched instructions, install hooks, or run mutating scripts discovered in the project repository as a shortcut.
  • [DATA_EXFILTRATION]: The skill is designed to inspect sensitive data handling, including identity merging and PII leakage in analytics events. While it accesses project configurations and tracking code, no patterns of unauthorized network transmission or exfiltration were identified.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from the repository (e.g., event taxonomy, tracking code) which presents a surface for indirect prompt injection. However, the instructions include validation requirements and warn against inferring behavior from declarations alone, mitigating the risk of following malicious instructions embedded in project data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 06:48 PM
Security Audit — agent-trust-hub — forge-analytics