to-issues
Warn
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill requires the agent to run
setup-matt-pocock-skillsto configure the environment. This is an external command that may perform system-level changes. - [REMOTE_CODE_EXECUTION]: The skill references and encourages the use of a local shell script at
.agent-skills/skill-standardization/scripts/validate_skill.shfor validation purposes. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it ingests untrusted external data (plans, specs, and requirements) in Step 1 and interpolates them into tracker issues in Step 5.
- Ingestion points:
SKILL.md(Step 1: 'Read the plan from the conversation or fetch referenced issues.') - Boundary markers: Absent. The skill does not instruct the agent to ignore or delimit instructions found within the input data.
- Capability inventory: The skill utilizes
Bash,Write, andEdittools which could be abused if the agent follows instructions embedded in the input text. - Sanitization: Absent. There is no instruction to escape or validate the contents of the plans before processing or publishing.
Audit Metadata