forge-integrations

Warn

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a shell command using Node.js: node ../../../.fullstack-forge/runtime/cli/src/composition-entry.js. This executes a local script from a relative path outside the skill's own directory.\n- [REMOTE_CODE_EXECUTION]: The skill implements an instruction redirection pattern, commanding the agent to load and follow its 'canonical playbook' from an external path (../../../.fullstack-forge/skills/forge-integrations/SKILL.md). This constitutes dynamic instruction loading from a computed path, which obscures the actual behavior of the skill from static analysis.\n- [COMMAND_EXECUTION]: The skill mentions administrative commands such as forge doctor and forge update all to be run if the installation is 'damaged', which involves further command execution and potential system modification.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 6, 2026, 06:48 PM
Security Audit — agent-trust-hub — forge-integrations