forge-persona

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

该技能与其声明目的基本一致,没有明确外部下载、凭证窃取或数据外传证据,因此不像恶意投毒技能;但它以处理真实第三方私密素材并模拟其身份表达为核心,隐私与冒充风险都偏高,且本地脚本来源不可验证、权限面较宽。整体应判定为 SUSPICIOUS,而非 BENIGN。

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
Apr 7, 2026, 07:47 AM
Package URL
pkg:socket/skills-sh/YIKUAIBANZI%2Fforge-skill%2Fforge-persona%2F@abab786d636e415d73e2e8c46c445e1fb613994b