forge-uploads
Warn
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: MEDIUMCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute a local Node.js script located at
../../../.fullstack-forge/runtime/cli/src/composition-entry.js. This execution is used to generate a composition file (.forge/composition.json) that dictates which subsequent instruction paths are loaded. - [COMMAND_EXECUTION]: The skill refers to external management commands
forge doctorandforge update allfor installation maintenance. These commands imply the ability to perform system-level checks and potentially fetch updates from the network. - [PROMPT_INJECTION]: The skill uses directive language instructing the agent to "follow it exactly" and "Stop and report" if certain conditions are not met. While intended for framework integrity, such instructions can be used to override standard agent reasoning if the resolved content is untrusted.
Audit Metadata