The skill lacks defined tool constraints and mandates opaque, unverified external dependencies, creating an insecure execution chain that prevents proper security auditing and risk assessment.
npx skills add https://github.com/mattpocock/skillsThe skill mandates the use of multiple external skills (/codebase-design, /grilling, /domain-modeling) without verifying their existence or safety, creating a complex, opaque execution chain. [ensemble: confirmed by 3/3 passes; severity set to the agreed median (ADR-0067).]
run the /grilling skill to walk the design tree... run the /domain-modeling skill to keep the domain model current
Skill body contains no code blocks or usage examples, making it harder for users to evaluate.
SKILL.md links to "HTML-REPORT.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[HTML-REPORT.md](HTML-REPORT.md)
Skill does not specify a license field. Specifying a license helps users understand usage terms.
[](https://mondoo.com/ai-agent-security/skills/github/mattpocock/skills/improve-codebase-architecture)<a href="https://mondoo.com/ai-agent-security/skills/github/mattpocock/skills/improve-codebase-architecture"><img src="https://mondoo.com/ai-agent-security/api/badge/github/mattpocock/skills/improve-codebase-architecture.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/mattpocock/skills/improve-codebase-architecture.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.