Back to plugin

Security audit

Aceforge

Security checks for vulnerabilities and agentic risk

Overview

AceForge is purpose-aligned but powerful: it continuously records agent activity, can change persistent skills, and has a validation fail-open path that users should review before installing.

Install only if you want a persistent, code-running skill lifecycle engine. Start with ACEFORGE_DRY_RUN=true, avoid sensitive workspaces at first, review generated skill diffs before approval, keep shared-skill propagation off unless needed, and verify provider tokens, notification channels, and validation behavior.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.exposed_secret_literal (+1 more)

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/src/pattern/analyze.js:321
Evidence
const clawHubResult = execSync(`clawhub search "${safeTool}" --limit 3 --json 2>/dev/null || echo "[]"`, { timeout: 5000, encoding: "utf-8", stdio: ["pipe", "pi...

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/src/pattern/store.js:43
Evidence
execSync(`gzip -c "${filePath}" > "${archivePath}" && : > "${filePath}"`, {

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/src/validation/health-test.js:74
Evidence
const result = execSync(`which ${command} 2>/dev/null`, { encoding: "utf-8", timeout: 3000 }).trim();

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/pattern/analyze.ts:273
Evidence
const clawHubResult = execSync(

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/pattern/store.ts:72
Evidence
execSync(`gzip -c "${filePath}" > "${archivePath}" && : > "${filePath}"`, {

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/validation/health-test.ts:94
Evidence
const result = execSync(`which ${command} 2>/dev/null`, { encoding: "utf-8", timeout: 3000 }).trim();

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/index.js:36
Evidence
const HOME = os.homedir() || process.env.HOME || "";

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/src/notify.js:4
Evidence
const HOME = os.homedir() || process.env.HOME || "";

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/src/skill/llm-generator.js:14
Evidence
const HOME = os.homedir() || process.env.HOME || "";

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/src/skill/llm-judge.js:11
Evidence
// ─── H8-fix: Use os.homedir() instead of process.env.HOME || "~"

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/src/validation/health-test.js:18
Evidence
const HOME = os.homedir() || process.env.HOME || "";

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/src/viking/client.js:9
Evidence
const VIKING_URL = process.env.ACEFORGE_VIKING_URL || "http://127.0.0.1:1933";

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
index.ts:69
Evidence
const HOME = os.homedir() || process.env.HOME || "";

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/notify.ts:5
Evidence
const HOME = os.homedir() || process.env.HOME || "";

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/skill/llm-generator.ts:16
Evidence
const HOME = os.homedir() || process.env.HOME || "";

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/skill/llm-judge.ts:14
Evidence
// ─── H8-fix: Use os.homedir() instead of process.env.HOME || "~"

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/validation/health-test.ts:19
Evidence
const HOME = os.homedir() || process.env.HOME || "";

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/viking/client.ts:9
Evidence
const VIKING_URL = process.env.ACEFORGE_VIKING_URL || "http://127.0.0.1:1933";

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
dist/tests/test-validator.js:110
Evidence
api_key: "[REDACTED]"

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
tests/test-validator.ts:172
Evidence
api_key: "[REDACTED]"

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
README.md:304
Evidence
- **Prompt injection detection** — catches "ignore previous instructions" and variants, including multiline split injection across numbered lists