forge-cost

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a local Node.js script at ../../../.fullstack-forge/runtime/cli/src/composition-entry.js. This script is part of the tool's runtime environment and is used to calculate workload costs.
  • [COMMAND_EXECUTION]: The agent is directed to load its primary instruction set from a central playbook located at ../../../.fullstack-forge/skills/forge-cost/SKILL.md. This is an architectural choice for the 'managed adapter' to ensure the agent uses the most up-to-date vendor instructions.
  • [COMMAND_EXECUTION]: The skill references local configuration files such as .forge/composition.json to guide the agent's behavior, which is a standard pattern for the Fullstack Forge ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 06:48 PM
Security Audit — agent-trust-hub — forge-cost