domain-context
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references an external GitHub repository (mattpocock/skills) as a source for companion functionality.\n- [COMMAND_EXECUTION]: Instructions include the use of the npx skills add command to install additional functional modules from a third-party repository.\n- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface because it is instructed to read and interpret existing Markdown documentation within a repository.\n
- Ingestion points: SKILL.md (Instructions to search for and read existing glossaries, domain guides, and ADRs in the local repository).\n
- Boundary markers: Absent.\n
- Capability inventory: SKILL.md (Updating existing files and creating new Markdown files based on ingested content).\n
- Sanitization: No sanitization or validation of the ingested document content is described.
Audit Metadata