4 min read

Matt Pocock Skills: Engineering Workflows for Coding Agents (GitHub, Scanned)

Matt Pocock's own agent skills for planning, testing and reviewing code instead of vibe coding.

Matt Pocock Skills logo
✅
Scan: safe. Nothing to warn about. It is almost entirely Markdown instructions, with no installers, no hooks and nothing that reaches the network. Scanned Oct 8, 2026; the full report is below.

This is the set of agent skills Matt Pocock, the TypeScript teacher behind Total TypeScript and AI Hero, says he uses every day, published straight from his own .agents directory. The skills are small Markdown instruction files aimed at the ways coding agents usually go wrong: building the wrong thing, talking in vague terms, shipping code that does not work, and piling up tangled design. The best known are /grill-me and /grill-with-docs, which make the agent interview you about a change until every open question is settled, with the second one also keeping a GLOSSARY.md of your project's terms and writing decision records as it goes.

Around those sit skills for turning a conversation into a spec and then into tickets, implementing that work with a red-green-refactor /tdd loop, diagnosing hard bugs, reviewing a diff against both your coding standards and the original spec, and surveying a codebase for places where the design could be simplified. The Claude Code plugin bundles 27 of them; a /setup-matt-pocock-skills step asks once per repository which issue tracker, triage labels and docs folder to use.

At about 281,000 stars it is one of the most-starred skills repositories on GitHub. It is MIT-licensed, works with Claude Code, Codex, GitHub Copilot, Gemini CLI and other agents through the npx skills installer, and the README is explicit that the skills are meant to be small and edited to suit you, rather than a framework that owns your process.

Who it is for

Developers who use Claude Code, Codex or a similar agent on real codebases and want short, composable habits (interview first, test first, review against the spec) rather than a heavyweight methodology.

Getting started

1. Claude Code: install the plugin from Anthropic's official marketplace

claude plugin install mattpocock-skills@claude-plugins-official

2. Codex: add the marketplace, then the plugin

codex plugin marketplace add mattpocock/skills && codex plugin add mattpocock-skills@mattpocock

3. Any other agent, as editable files

npx skills@latest add mattpocock/skills

4. Then, once per repository, inside your agent

/setup-matt-pocock-skills

The last command is typed inside Claude Code (or your agent), not a shell. Pick one install method per agent: the plugin updates itself, the npx skills route copies files you update by hand, and installing both gives you every skill twice.

Safety scan

We cloned mattpocock/skills at commit b0618bc on Oct 8, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.

  • No secrets, no suspicious code patterns, no committed binaries and no installer scripts across 187 files and about 8,900 lines, most of them Markdown you can read in full. The only external host in the files is dashboard.stripe.com, mentioned in a document.
  • A second, skill-specific pass looked for invisible Unicode, prompt-injection phrases, exfiltration hosts, credential paths, pipe-to-shell commands, long base64 blobs and plugin hook files. It found nothing.
  • The 9 known advisories (7 high) are all in package-lock.json, which belongs to the @changesets tooling the maintainer uses to version the repository. Those are development dependencies of a private package and are never installed when you add the skills.
  • The one hook-related skill, git-guardrails-claude-code in the misc folder, is not in the plugin. If you choose to use it, it copies a small script that blocks git push, reset --hard and similar commands into your Claude Code settings, which is a safety feature rather than a risk.
  • Three workflows, none using pull_request_target. Licence present; no security policy, contributing guide, Dependabot or CodeQL.

What the scanner counted

CheckResult
SecretsNone found.
Suspicious codeNone found.
Install-time codeNone: nothing runs at install beyond the package manager itself.
Committed binariesNone.
CI workflows3 workflows. None use pull_request_target. 1 of 1 third-party action pinned to a tag rather than a commit.
Network hosts1 distinct host referenced from source; most often dashboard.stripe.com. No URLs to bare IP addresses.
Known vulnerabilities9 advisories across 110 pinned packages: 0 critical, 7 high, 2 moderate, 0 low. package-lock.json: 111 packages, 9 advisories.
Project hygieneHas licence file. Missing security policy, automated dependency updates, CodeQL, contributing guide.
OpenSSF ScorecardNot scored: the project is not in Scorecard's weekly index.

The raw findings

Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.

Worst known vulnerabilities (9 of 9)
AdvisorySeverityPackageSummary
GHSA-vfj7-8cjw-p6xmhighbraces@3.0.3braces vulnerable to stack-exhaustion denial of service through deeply nested patterns
GHSA-2883-xcg3-v3hhhighjs-yaml@4.2.0js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
GHSA-52cp-r559-cp3mhighjs-yaml@4.2.0js-yaml: YAML merge-key chains can force quadratic CPU consumption
GHSA-5p4m-2wfm-xmqjhighjs-yaml@4.2.0JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) - CVE-2026-59870 fix not backported
GHSA-2883-xcg3-v3hhhighjs-yaml@3.14.2js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
GHSA-52cp-r559-cp3mhighjs-yaml@3.14.2js-yaml: YAML merge-key chains can force quadratic CPU consumption
GHSA-5p4m-2wfm-xmqjhighjs-yaml@3.14.2JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) - CVE-2026-59870 fix not backported
GHSA-h67p-54hq-rp68moderatejs-yaml@3.14.2JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases
GHSA-hp3w-g68c-fv3cmoderatesprintf-js@1.0.3sprintf-js vulnerable to denial of service through unbounded precision specifiers

By the numbers

Stars280.8K
Forks23.5K
Contributors8
Commits543
Open issues150
Open pull requests13
Releases9
Latest releasev1.3.1
LicenceMIT
Main languageShell
Project age8 months
Last pushOct 8, 2026
Tracked files187
Lines of code8,870
Checkout size734 KB

Lines by language: Markdown 7,877, YAML 390, Shell 352, JavaScript 138, JSON 113.

Questions

Is Matt Pocock Skills free?

Yes. The repository is MIT-licensed and free to use, copy and change. You still need a coding agent to run the skills, such as Claude Code, Codex or Copilot, under that product's own pricing. The newsletter and courses linked from the README are separate and optional.

Do I have to use all of the skills?

No. They are designed to be small and composable. Many people start with /grill-me or /grill-with-docs before a change and /tdd during it, and add the spec, ticket and review skills later. The npx skills installer lets you pick individual skills, and the files are meant to be edited.

Does it work outside Claude Code?

Yes. The README gives install steps for Codex, GitHub Copilot (CLI and VS Code) and Gemini CLI, and the npx skills installer covers Cursor, OpenCode, Windsurf, Amp and other agents that read the Agent Skills format.


This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.