setup-matt-pocock-skills
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from repository files that could be influenced by external actors, presenting a potential surface for indirect prompt injection.
- Ingestion points: Reads files from the repository root including
AGENTS.md,CLAUDE.md,CONTEXT.md, and.git/configto determine the current configuration state. - Boundary markers: None explicitly defined in the ingested files; however, the skill logic requires presenting findings to the user for confirmation before taking action.
- Capability inventory: The skill has the ability to execute shell commands via
Bashand modify files usingWriteandEdittools. - Sanitization: The skill incorporates a human-in-the-loop review process, requiring user confirmation before any edits are performed.
- [COMMAND_EXECUTION]: The skill utilizes command-line tools to interact with the repository and external hosting platforms.
- Evidence: Execution of
git remote -vto identify repository remotes. - Evidence: Use of
ghandglabCLI tools for interaction with GitHub and GitLab issue trackers as defined in the companion documentation files.
Audit Metadata