setup-matt-pocock-skills
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes local repository files and git configuration to recommend setup options.\n
- Ingestion points: The skill reads
git remote -v,.git/config,package.json, and existing documentation files likeCLAUDE.mdandAGENTS.mdto identify the repository's configuration state.\n - Boundary markers: No explicit delimiters or boundary markers are used when processing the data read from these local files to separate untrusted content from the agent's instructions.\n
- Capability inventory: The skill writes configuration files to the
docs/agents/directory and modifies root-level instruction files (CLAUDE.mdorAGENTS.md) based on the ingested data.\n - Sanitization: Input from the repository files is not explicitly sanitized before being incorporated into the suggested configuration and the resulting documentation files.\n- [COMMAND_EXECUTION]: The skill utilizes and provides templates for system command-line tools to explore the environment and manage project workflows.\n
- Evidence: The process involves executing
git remote -vto probe repository origins. Furthermore, the provided templates for GitHub and GitLab integrations specify the use of theghandglabCLIs to manage issues, pull requests, and repository metadata.
Audit Metadata