vector-forge

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s core behavior is coherent with mutation-driven crypto test-vector generation and does not request secrets or route data to obvious exfiltration services. However, it requires installation/execution of an unverified `trailmark` dependency and also instructs use of another skill (`genotoxic`), creating both supply-chain and transitive-trust risk disproportionate to a fully self-contained testing guide.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
Mar 31, 2026, 10:44 PM
Package URL
pkg:socket/skills-sh/trailofbits%2Fskills%2Fvector-forge%2F@4bca14a4d484954546191ae2b6e0283014c6b0a6