setup-matt-pocock-skills

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Uses git remote to identify the repository host and provides instructions for the agent to use gh or glab CLI tools for issue management activities.
  • [PROMPT_INJECTION]: The skill ingests data from local repository files and remote issue tracker comments, creating an indirect injection surface.
  • Ingestion points: Reading AGENTS.md, CLAUDE.md, and issue data via gh/glab in SKILL.md.
  • Boundary markers: Absent.
  • Capability inventory: File system writes to docs/agents/ and command execution through supported issue tracker CLIs.
  • Sanitization: Mitigated by mandatory human-in-the-loop verification where the user must approve all proposed content before files are written.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 10:44 AM
Security Audit — agent-trust-hub — setup-matt-pocock-skills