forge-integrations

Warn

Audited by Socket on Aug 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is coherent, but the skill is only a pointer and asks the agent to execute an unverified local runtime and dynamically load more guidance from local composition files. There is no clear credential theft or exfiltration in this adapter, but install/runtime trust and transitive instruction loading make it medium risk until the Fullstack Forge runtime provenance is verified.

Confidence: 79%Severity: 56%
Audit Metadata
Analyzed At
Aug 6, 2026, 06:49 PM
Package URL
pkg:socket/skills-sh/thethunderbolt%2Ffullstack-forge-skill%2Fforge-integrations%2F@84e420996d2d50aee25ea4c850df56b594ccf0294578575dc8972a9d7be0781a
Security Audit — socket — forge-integrations