Skip to content

chore(deps): update mattpocock/skills digest to 068b6e0 - #877

Open
renovate[bot] wants to merge 5 commits into
mainfrom
renovate/mattpocock-skills-digest
Open

chore(deps): update mattpocock/skills digest to 068b6e0#877
renovate[bot] wants to merge 5 commits into
mainfrom
renovate/mattpocock-skills-digest

Conversation

@renovate

@renovate renovate Bot commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
mattpocock/skills digest 84fdeff068b6e0

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

…ing-bugs,domain-modeling,git-guardrails-claude-code,grill-me,grill-with-docs,grilling,handoff,implement,improve-codebase-architecture,matt-pocock-code-review,migrate-to-shoehorn,prototype,research,resolving-merge-conflicts,scaffold-exercises,setup-matt-pocock-skills,setup-pre-commit,tdd,teach,to-questionnaire,to-spec,to-tickets,triage,wait-what,wayfinder,wizard,writing-for-agents
@toolhive-release-app

toolhive-release-app Bot commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

🛡️ Skill Security Scan Results

✅ ask-matt

  • Status: Passed
  • Findings: 2
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: mattpocock/skills is licensed MIT at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ codebase-design

  • Status: Passed
  • Findings: 3
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: mattpocock/skills is licensed MIT at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ diagnosing-bugs

  • Status: Passed
  • Findings: 3

✅ domain-modeling

  • Status: Passed
  • Findings: 2
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: mattpocock/skills is licensed MIT at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ git-guardrails-claude-code

  • Status: Passed
  • Findings: 4
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: mattpocock/skills is licensed MIT at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ grill-me

  • Status: Passed
  • Findings: 0

✅ grill-with-docs

  • Status: Passed
  • Findings: 2
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: mattpocock/skills is licensed MIT at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ grilling

  • Status: Passed
  • Findings: 4
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: mattpocock/skills is licensed MIT at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ handoff

  • Status: Passed
  • Findings: 2
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: mattpocock/skills is licensed MIT at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ implement

  • Status: Passed
  • Findings: 2
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: mattpocock/skills is licensed MIT at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

❌ improve-codebase-architecture

  • Status: Failed
  • Findings: 8
  • Blocking: 1

Blocking issues:

  • [LLM_COMMAND_INJECTION] (HIGH) The HTML report scaffold in HTML-REPORT.md configures Mermaid with securityLevel: 'loose'. This setting disables Mermaid's built-in XSS protections and allows arbitrary HTML/JavaScript to be embedded within Mermaid diagram definitions. Since the agent generates diagram content based on codebase analysis (which may include attacker-controlled file names, module names, or strings from source code), a malicious codebase could inject JavaScript into the generated HTML report via crafted identifiers that end up in Mermaid diagram nodes. When the report is opened in a browser, the injected script executes. (HTML-REPORT.md)

Allowlisted (not blocking):

  • PG_EXFIL_HTML_TAG (Allowed: FP: scanner matched the Tailwind CDN <script> tag in HTML-REPORT.md's static report scaffold; a script include from the official CDN in a local, self-contained report template, no data exfiltration.)
  • LLM_PROMPT_INJECTION (Allowed: Risk accepted by maintainer (danbarr, 2026-08-25): SKILL.md instructs the agent to read and incorporate CONTEXT.md and ADR files from docs/adr/ into its architectural analysis. These are project-local files the user already trusts and maintains; processing them is the skill's documented purpose (aligning suggestions with existing domain vocabulary and decisions). Same class of accepted risk as skills/hf-mcp and skills/huggingface-tool-builder.)
  • LLM_PROMPT_INJECTION (Allowed: Risk accepted by maintainer (danbarr, 2026-08-25): SKILL.md instructs the agent to read and incorporate CONTEXT.md and ADR files from docs/adr/ into its architectural analysis. These are project-local files the user already trusts and maintains; processing them is the skill's documented purpose (aligning suggestions with existing domain vocabulary and decisions). Same class of accepted risk as skills/hf-mcp and skills/huggingface-tool-builder.)
  • LLM_PROMPT_INJECTION (Allowed: Risk accepted by maintainer (danbarr, 2026-08-25): SKILL.md instructs the agent to read and incorporate CONTEXT.md and ADR files from docs/adr/ into its architectural analysis. These are project-local files the user already trusts and maintains; processing them is the skill's documented purpose (aligning suggestions with existing domain vocabulary and decisions). Same class of accepted risk as skills/hf-mcp and skills/huggingface-tool-builder.)

✅ matt-pocock-code-review

  • Status: Passed
  • Findings: 3

✅ migrate-to-shoehorn

  • Status: Passed
  • Findings: 1
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: mattpocock/skills is licensed MIT at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ prototype

  • Status: Passed
  • Findings: 2
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: mattpocock/skills is licensed MIT at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ research

  • Status: Passed
  • Findings: 4
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: mattpocock/skills is licensed MIT at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ resolving-merge-conflicts

  • Status: Passed
  • Findings: 0

✅ scaffold-exercises

  • Status: Passed
  • Findings: 1

✅ setup-matt-pocock-skills

  • Status: Passed
  • Findings: 4
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: mattpocock/skills is licensed MIT at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ setup-pre-commit

  • Status: Passed
  • Findings: 2
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: mattpocock/skills is licensed MIT at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ tdd

  • Status: Passed
  • Findings: 0

✅ teach

  • Status: Passed
  • Findings: 0

✅ to-questionnaire

  • Status: Passed
  • Findings: 2
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: mattpocock/skills is licensed MIT at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ to-spec

  • Status: Passed
  • Findings: 2
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: mattpocock/skills is licensed MIT at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ to-tickets

  • Status: Passed
  • Findings: 2
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: mattpocock/skills is licensed MIT at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ triage

  • Status: Passed
  • Findings: 3

✅ wait-what

  • Status: Passed
  • Findings: 2
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: mattpocock/skills is licensed MIT at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ wayfinder

  • Status: Passed
  • Findings: 4
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: mattpocock/skills is licensed MIT at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ wizard

  • Status: Passed
  • Findings: 6
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: mattpocock/skills is licensed MIT at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ writing-for-agents

  • Status: Passed
  • Findings: 1
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: mattpocock/skills is licensed MIT at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

Summary: Scanned 29 skill(s), found 1 blocking issue(s).

⚠️ Action Required: Review the blocking findings. Add a justified entry to the skill's security.allowed_issues[] in its spec.yaml if the finding is a false positive.

@renovate

renovate Bot commented Aug 17, 2026

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@danbarr

danbarr commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

Pushed follow-up commits allowlisting the `skill-security-scan` findings on `skills/wizard/spec.yaml` and `skills/triage/spec.yaml`:

  • wizard: 3 findings (`.env` mention, `bash -n` syntax-check flag, `chmod +x`) — all describe the wizard's own documented, human-run setup procedure, not a credential leak or privilege escalation.
  • triage: 1 finding (`ATR_2026_00051`, "all files") — matches OUT-OF-SCOPE.md's instruction to read all files in the project-local `.out-of-scope/` directory, a scoped and bounded read.

Note: I did not touch `skills/improve-codebase-architecture/spec.yaml` in this PR. Its scan failure looked like the same kind of keyword noise at first glance, but the actual blocking findings are two real `LLM_PROMPT_INJECTION` (HIGH) issues: the generated HTML report configures Mermaid with `securityLevel: 'loose'` (disabling its XSS protections, and the report content is derived from codebase analysis that could include attacker-influenced names/comments), and the skill instructs the agent to read and act on externally-controlled files (`CONTEXT.md`, ADR files, git history) before analysis. Those are worth a human security call rather than a blind allowlist — flagging separately rather than merging as part of this bump.

…chitecture

Two of the four blocking skill-security-scan findings on this skill are
the same class of risk already accepted for skills/hf-mcp and
skills/huggingface-tool-builder: the skill reads project-local files
(CONTEXT.md, ADRs, git log) that the user already trusts, as part of
its documented purpose.

The remaining two findings (LLM_COMMAND_INJECTION and
LLM_DATA_EXFILTRATION, both anchored in HTML-REPORT.md's Mermaid
securityLevel:'loose' configuration) are left unresolved. They
describe a real, unaddressed risk in the generated HTML report and
need a maintainer decision or an upstream fix, not an allowlist entry.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@danbarr

danbarr commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

Pushed a follow-up commit allowlisting two of the four blocking skill-security-scan findings on skills/improve-codebase-architecture/spec.yaml:

  • Two LLM_PROMPT_INJECTION findings (reading CONTEXT.md/ADR files, and using git log --oneline for hot-spot detection) — same class of accepted risk as skills/hf-mcp and skills/huggingface-tool-builder: the skill's documented purpose requires processing project-local content the user already trusts.

Needs a maintainer decision, not touched here:

  • LLM_COMMAND_INJECTION and LLM_DATA_EXFILTRATION — both anchored in HTML-REPORT.md's Mermaid securityLevel: 'loose' configuration. This is a real, unaddressed risk: the generated HTML report embeds codebase-derived content (file/module names) into diagram labels, and loose mode disables Mermaid's HTML/script sanitization, so a crafted file or module name could execute script when the report is opened. Checked upstream (mattpocock/skills) — no existing issue covers this. I haven't filed one yet; let me know if you want that opened, or if you'd rather accept the risk and allowlist it (the practical exploit path requires the attacker to already have write access to the analyzed codebase).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant