forge-storage

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a Node.js script located at "../../../.fullstack-forge/runtime/cli/src/composition-entry.js" to manage its runtime composition. This is standard behavior for an integrated tool adapter.
  • [PROMPT_INJECTION]: The skill loads its operational instructions from a canonical playbook located at "../../../.fullstack-forge/skills/forge-storage/SKILL.md". Ingestion points: The agent is directed to read and follow an external file and a composition JSON file. Boundary markers: None present in the pointer file; instructions rely on the agent's adherence to the canonical playbook. Capability inventory: Local script execution via Node.js. Sanitization: The skill assumes the integrity of the Fullstack Forge installation directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 06:48 PM
Security Audit — agent-trust-hub — forge-storage