bmad-sprint-planning
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from project epic files and planning artifacts to generate status reports.\n
- Ingestion points: The Python script
scripts/sprint_plan.pyreads content from markdown files in the{planning_artifacts}directory. Instructions inreferences/readiness-gate.mdalso direct the agent to inventory and assess various project documents like briefs, specs, and UX outputs.\n - Boundary markers: The processing script uses strict regular expressions to parse epic and story headers and explicitly ignores content within fenced code blocks.\n
- Capability inventory: Capabilities are limited to local file system writes for the status file and execution of local Python scripts. No network access or privilege escalation mechanisms are utilized.\n
- Sanitization: The skill generates structured YAML using a library designed to preserve formatting and ensure data integrity, reducing the risk of schema confusion.\n- [DYNAMIC_EXECUTION]: The Python script
scripts/sprint_plan.pyuses theruamel.yamllibrary to load existing sprint status files.\n - Evidence: The script initializes a
ruamel.yaml.YAMLinstance and calls the.load()method on file handles inscripts/sprint_plan.pyandscripts/tests/test_sprint_plan.py.\n - Context: The use of the
YAMLinstance with the default round-trip type (typ='rt') is the standard, safe API for this library and is used here to maintain comments and formatting in the YAML file. It does not introduce the security vulnerabilities typically associated with unsafe YAML loaders in other libraries.
Audit Metadata