scrum-master-agent
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted sprint data, such as story titles and descriptions, from JSON, CSV, and YAML files. This content is interpolated into the agent's context when generating reports, creating a surface for indirect prompt injection where malicious instructions in the data could influence the agent's behavior.
- Ingestion points:
parse_input.pyprocesses user-supplied sprint exports. - Boundary markers: Absent; the data is mapped into internal objects and directly formatted into output strings.
- Capability inventory: The skill has network capabilities (POST requests) via
notify_channels.pyand file-read capabilities through the agent's environment. - Sanitization: Absent; the skill normalizes the data structure but does not sanitize text content for potential injection sequences.
- [DATA_EXFILTRATION]: The
notify_channels.pymodule allows the agent to send sprint metrics and risk summaries to external Slack and Microsoft Teams webhooks. While these notification channels are user-configured via environment variables or a configuration file, the skill performs network POST operations to these external services. - [EXTERNAL_DOWNLOADS]: The skill imports the
yaml(PyYAML) library inparse_input.pyandnotify_channels.py, which is not part of the standard Python library. The skill does not provide arequirements.txtor similar dependency manifest, although it does include a fallback mechanism to JSON in case the library is missing.
Audit Metadata