forge-new

Warn

Audited by Socket on Aug 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is coherent for a project-bootstrap adapter, but the actual behavior is mostly deferred to unseen local playbooks and runtime code. The main risk is trust in unreviewed local Fullstack Forge components rather than overt malicious behavior in this adapter itself.

Confidence: 82%Severity: 52%
Audit Metadata
Analyzed At
Aug 6, 2026, 06:49 PM
Package URL
pkg:socket/skills-sh/thethunderbolt%2Ffullstack-forge-skill%2Fforge-new%2F@8907bc051a7fb1df34e28bb4f309892c1d6f798f4c90a04a0e5612a0653bb6aa
Security Audit — socket — forge-new