Loading
heating the forge...
ForgeCat
Agent Profiles
Docs
Sell Agents
Feedback
@yoochankim/sori — Security Risk Report | ForgeCat
forgecat
/
yoochankim
/
sori
/
security
sori
Security risk report for
@yoochankim/sori
v0.1.3
Source Integrity
Low
Profile is self-contained with no external dependencies or supply-chain references.
No instructions to fetch remote code, install packages, or load external profiles.
References to local files (CONTRIBUTING.md, skills/sori-recorder/SKILL.md) are internal documentation, not external sources.
Agent Intent
Low
Content describes legitimate recording control and privacy boundaries; no prompt injection, role hijacking, or system prompt leakage attempts.
Instructions are defensive and user-protective: explicit consent required, no background collection, no unauthorized uploads or permission changes.
No guidance poisoning: does not instruct weakening security, installing backdoors, or systematically steering outputs toward attacker goals.
Details
Evidence
"Start microphone or system-audio recording only after an explicit request from the user."
"Do not upload, transcribe, attach, or share audio without a request that names the intended action."
"Do not change macOS privacy permissions or the permissions on ~/Sori without explicit approval."
Permissions
Low
Skill operates a single local tool (Sori CLI) with scoped, user-initiated commands (start, stop, status, list, devices, set-mic).
No file deletion, shell execution, or filesystem mutation beyond the Sori recording directory; no network access or subagent authority.
Authority is narrowly matched to the stated function: local recording control and verification only.
Details
Evidence
"This skill does not transcribe audio or change Sori source code."
"Do not change macOS privacy permissions, switch microphones, or delete recordings unless the user asks."
CLI commands are read-only (status, list, devices) or user-authorized state changes (start, stop, set-mic).
MCP Risk
Low
No MCP servers declared in the profile.
Skill relies on local Sori CLI binary with JSON output; no hidden instructions in tool descriptions or arbitrary binary execution.
No external network access, unrestricted filesystem, or required environment credentials.
Details
Evidence
"(none)" in MCP servers section.
All operations use local CLI: sori status, sori start, sori stop, sori list, sori devices, sori set-mic.
Evaluation Details
Status
Completed
Checks completed
4/4
Flagged
0
Evaluated
9/3/2026