forge-uploads

Warn

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: MEDIUMCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a local Node.js script located at ../../../.fullstack-forge/runtime/cli/src/composition-entry.js. This execution is used to generate a composition file (.forge/composition.json) that dictates which subsequent instruction paths are loaded.
  • [COMMAND_EXECUTION]: The skill refers to external management commands forge doctor and forge update all for installation maintenance. These commands imply the ability to perform system-level checks and potentially fetch updates from the network.
  • [PROMPT_INJECTION]: The skill uses directive language instructing the agent to "follow it exactly" and "Stop and report" if certain conditions are not met. While intended for framework integrity, such instructions can be used to override standard agent reasoning if the resolved content is untrusted.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 6, 2026, 06:48 PM
Security Audit — agent-trust-hub — forge-uploads