texforge

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill’s core purpose is coherent for a LaTeX CLI, but its install and execution model is high-risk: remote pipe-to-shell installers plus an undocumented automatic binary download/execution path for Tectonic. No credential harvesting or obvious exfiltration is described, so this is better classified as suspicious/high-risk supply-chain behavior rather than confirmed malware.

Confidence: 80%Severity: 76%
Audit Metadata
Analyzed At
Apr 1, 2026, 02:33 PM
Package URL
pkg:socket/skills-sh/jheisonmb%2Fskills%2Ftexforge%2F@dcaea0a6a304106dfd11d7f9232facd161caaae2