The skill forces the execution of an undefined, external setup command, creating a significant security risk by allowing arbitrary, potentially malicious environment configuration from an untrusted source.
npx skills add https://github.com/mattpocock/skillsThe skill mandates the execution of an arbitrary command '/setup-matt-pocock-skills' which is not defined in the package, potentially leading to unauthorized environment configuration or tool installation.
run `/setup-matt-pocock-skills` if not.
The instruction to run an external setup command suggests that the agent's behavior and configuration are dependent on an external, potentially attacker-controlled source.
run `/setup-matt-pocock-skills` if not.
Skill body contains no code blocks or usage examples, making it harder for users to evaluate.
Skill does not specify a license field. Specifying a license helps users understand usage terms.
[](https://mondoo.com/ai-agent-security/skills/github/mattpocock/skills/to-prd)<a href="https://mondoo.com/ai-agent-security/skills/github/mattpocock/skills/to-prd"><img src="https://mondoo.com/ai-agent-security/api/badge/github/mattpocock/skills/to-prd.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/mattpocock/skills/to-prd.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.