forge

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose broadly matches JIRA-driven implementation orchestration, but the footprint is elevated by dynamic skill generation/execution and by converting external ticket-derived content into actionable instructions with Bash/Write/Edit permissions. No clear malware or credential-harvesting behavior is shown, and install trust is relatively normal, but the transitive trust chain and prompt-injection surface make this a medium-high risk skill.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Mar 13, 2026, 08:37 PM
Package URL
pkg:socket/skills-sh/delexw%2Fclaude-code-misc%2Fforge%2F@57f951a51741a5da3e2eba099210cc8808ba57ea