forge-security
Warn
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: MEDIUMCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute a local Node.js script:
node ../../../.fullstack-forge/runtime/cli/src/composition-entry.js security compose --root <repository-root> --json. This command execution is part of the 'Fullstack Forge' framework's operation but involves running code from a path outside the skill's immediate directory. - [COMMAND_EXECUTION]: The skill delegates its primary functionality to an external file by instructing the agent to 'Read the canonical playbook now and follow it exactly' at
../../../.fullstack-forge/skills/forge-security/SKILL.md. This pattern externalizes the agent's instructions, making the security posture dependent on the content of the referenced file.
Audit Metadata