forge-storage
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a Node.js script located at "../../../.fullstack-forge/runtime/cli/src/composition-entry.js" to manage its runtime composition. This is standard behavior for an integrated tool adapter.
- [PROMPT_INJECTION]: The skill loads its operational instructions from a canonical playbook located at "../../../.fullstack-forge/skills/forge-storage/SKILL.md". Ingestion points: The agent is directed to read and follow an external file and a composition JSON file. Boundary markers: None present in the pointer file; instructions rely on the agent's adherence to the canonical playbook. Capability inventory: Local script execution via Node.js. Sanitization: The skill assumes the integrity of the Fullstack Forge installation directory.
Audit Metadata