forge-recon
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes multiple reconnaissance commands using established cloud CLIs (
gcloud,aws,flyctl,wrangler). These are used for their primary intended purpose of infrastructure inventory. - [COMMAND_EXECUTION]: It uses local shell commands (
find,ls,cat) to detect Infrastructure-as-Code (IaC) files such as Terraform, Pulumi, and Docker Compose. - [DATA_EXPOSURE]: The skill intentionally scans for potential credential leaks in IaC files (API keys, secrets) to flag them as critical security risks for the user.
Audit Metadata