Forge · gyuha
An agent-engineering plugin for Claude Code: twenty-two fg- skills. fg-security audits a codebase for exploitable vulnerabilities (methodology vendored from cloudflare/security-audit-skill, MIT) with artefacts kept outside the repo, and routes severity-gated findings into fix-forward plans. Four form a loop that takes one task through a single cycle of ask·plan → execute → retro → done: ask·plan (fg-ask) is grill-with-docs-style conversational grilling, execute (fg-run) picks a task from the ba
Works with: Claude Code (native)
native: this artifact type is that client's own format
Install (Claude Code):
/plugin marketplace add jdforsythe/forge
/plugin install forge@forge- tashan score: 47.0
- Adoption: 1 repos
- Freshness: 95.0
- Evidence coverage: 59% of the inputs this score can use — the rest are unknown, and the score is discounted for it
- Health: active
- GitHub stars: 4
Security audit
Not scanned yet. We audit npm-published capabilities for known advisories, install-time scripts and permission surface; this one has no npm package we can resolve, or has not reached the queue.
You searched for one. Check the rest of your stack:
npx tashan-cli doctorReads the config already on your machine and names what is dead, deprecated or running code at install time. No account, nothing uploaded.
Forge · gyuha scores 47 today. Pro keeps the series, so you can see whether that is a project getting better or one on its way down.
- Every score since we started measuring, for any capability
- The named replacement when something you run is dying — not just that it is
tashan doctorover the config you already have, on your machine
Start a 7-day trial › Everything measured on this page stays free.
source ↗ · plugin:gyuha/forge/forge
Everything on this page is public evidence and free. What it cannot know is whether you run this — check your whole config, free, in the browser. tashan Pro adds the series behind each row and names a replacement for anything dying.
Already running this? Check your whole config — free, in your browser, nothing installed. Or npx tashan-cli doctor locally, which sends nothing at all.
Measured 2026-09-12 · scorer s5 · how · something wrong here?