setup-matt-pocock-skills

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from repository files that could be influenced by external actors, presenting a potential surface for indirect prompt injection.
  • Ingestion points: Reads files from the repository root including AGENTS.md, CLAUDE.md, CONTEXT.md, and .git/config to determine the current configuration state.
  • Boundary markers: None explicitly defined in the ingested files; however, the skill logic requires presenting findings to the user for confirmation before taking action.
  • Capability inventory: The skill has the ability to execute shell commands via Bash and modify files using Write and Edit tools.
  • Sanitization: The skill incorporates a human-in-the-loop review process, requiring user confirmation before any edits are performed.
  • [COMMAND_EXECUTION]: The skill utilizes command-line tools to interact with the repository and external hosting platforms.
  • Evidence: Execution of git remote -v to identify repository remotes.
  • Evidence: Use of gh and glab CLI tools for interaction with GitHub and GitLab issue trackers as defined in the companion documentation files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 02:14 PM
Security Audit — agent-trust-hub — setup-matt-pocock-skills