scrum-master
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses Python scripts including velocity_analyzer.py, sprint_health_scorer.py, and retrospective_analyzer.py to process sprint data files locally. These scripts utilize standard library functions for statistical calculation and do not execute external binary files or shell commands beyond their own invocation.
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes external JSON data files provided by the user (e.g., sprint_data.json). While this data is processed by Python scripts to generate summaries and recommendations for the agent, the deterministic nature of the scripts and the absence of unsafe interpolation minimize the risk of indirect injection attacks.
Audit Metadata