bmad-sprint-planning

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from project epic files and planning artifacts to generate status reports.\n
  • Ingestion points: The Python script scripts/sprint_plan.py reads content from markdown files in the {planning_artifacts} directory. Instructions in references/readiness-gate.md also direct the agent to inventory and assess various project documents like briefs, specs, and UX outputs.\n
  • Boundary markers: The processing script uses strict regular expressions to parse epic and story headers and explicitly ignores content within fenced code blocks.\n
  • Capability inventory: Capabilities are limited to local file system writes for the status file and execution of local Python scripts. No network access or privilege escalation mechanisms are utilized.\n
  • Sanitization: The skill generates structured YAML using a library designed to preserve formatting and ensure data integrity, reducing the risk of schema confusion.\n- [DYNAMIC_EXECUTION]: The Python script scripts/sprint_plan.py uses the ruamel.yaml library to load existing sprint status files.\n
  • Evidence: The script initializes a ruamel.yaml.YAML instance and calls the .load() method on file handles in scripts/sprint_plan.py and scripts/tests/test_sprint_plan.py.\n
  • Context: The use of the YAML instance with the default round-trip type (typ='rt') is the standard, safe API for this library and is used here to maintain comments and formatting in the YAML file. It does not introduce the security vulnerabilities typically associated with unsafe YAML loaders in other libraries.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:08 AM
Security Audit — agent-trust-hub — bmad-sprint-planning