setup-matt-pocock-skills

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill demonstrates an indirect prompt injection surface by ingesting data from the repository's existing configuration and documentation files to inform its scaffolding actions. \n
  • Ingestion points: Step 1 of SKILL.md directs the agent to read CLAUDE.md, AGENTS.md, .git/config, CONTEXT.md, and other files in docs/adr/ or .scratch/. \n
  • Boundary markers: The instructions do not define clear boundaries or provide warnings to disregard instructions found within these ingested files. \n
  • Capability inventory: The skill allows the agent to perform file write operations (e.g., creating docs/agents/issue-tracker.md) and execute shell commands via git, gh (GitHub CLI), and glab (GitLab CLI). \n
  • Sanitization: There is no explicit sanitization or verification process for the content read from the repository files before it is used to generate the new configuration documentation.
  • [EXTERNAL_DOWNLOADS]: The skill provides links to the official GitLab CLI (glab) repository and documentation at https://gitlab.com/gitlab-org/cli. This is a well-known and trusted service.
  • [COMMAND_EXECUTION]: The skill utilizes standard developer CLI tools including git, gh, and glab to perform repository exploration and issue management tasks. These operations are restricted to the repository's scope and standard developer workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 02:38 PM