forge-analytics
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes vendor-specific CLI tools such as
forgeandfullstack-forgeto perform automated audits. It includes a specific security safeguard instructing the agent to never execute fetched instructions, install hooks, or run mutating scripts discovered in the project repository as a shortcut. - [DATA_EXFILTRATION]: The skill is designed to inspect sensitive data handling, including identity merging and PII leakage in analytics events. While it accesses project configurations and tracking code, no patterns of unauthorized network transmission or exfiltration were identified.
- [PROMPT_INJECTION]: The skill ingests untrusted data from the repository (e.g., event taxonomy, tracking code) which presents a surface for indirect prompt injection. However, the instructions include validation requirements and warn against inferring behavior from declarations alone, mitigating the risk of following malicious instructions embedded in project data.
Audit Metadata