forge-verify
Fail
Audited by Socket on Mar 8, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The FORGE QA Agent (TEA) skill presents a coherent, self-contained auditing workflow focused on reviewing stories, tests, and architecture decisions. It relies on local files and memory/logging without downloading binaries, handling credentials, or contacting external services. The risk footprint is low and proportional to its stated purpose of QA auditing and governance. The only minor concern is the potential for automation to perform actions without explicit per-action approvals, but the described scope remains non-destructive and review-oriented.
Confidence: 98%
Audit Metadata