agentforge

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the overall workflow mostly matches the stated purpose, but the execution surface is not fully trustworthy because key `agentforge` commands/module paths are unverified. Local config scanning is somewhat broader than necessary, and GitHub-driven research plus file generation adds moderate prompt-injection risk. No clear credential theft or exfiltration path is shown, so this looks more like a risky/underspecified skill than confirmed malware.

Confidence: 82%Severity: 61%
Audit Metadata
Analyzed At
Mar 25, 2026, 04:47 AM
Package URL
pkg:socket/skills-sh/AlexAI-MCP%2FAgentForge%2Fagentforge%2F@a429306b173b709599cce75004a7083ec6c4928c