→ Publisher: host /.well-known/forge.json on the project homepage with { "publisher": "<github-login>" }
—Prompt-injection scan · not run+0/30
→ This entry exposes no inspectable source (a hosted endpoint), so there is nothing to scan. Publish an npm package or link a public repository to become scannable.
—Obfuscation / exfil scan · not run+0/20
→ This entry exposes no inspectable source (a hosted endpoint), so there is nothing to scan. Publish an npm package or link a public repository to become scannable.
Paste into Claude Code, Cursor, or any AI assistant to fix all gaps
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts — it cannot prove the absence of malicious code.