bmad-sprint-planning
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from markdown epic files and existing sprint status YAML files.\n
- Ingestion points: Reads markdown files within the planning artifacts directory (e.g., epics.md).\n
- Boundary markers: The sprint_plan.py script explicitly ignores content within fenced code blocks to prevent accidental parsing of code as planning data.\n
- Capability inventory: The skill has the ability to write to the file system to update or fix the sprint-status.yaml file.\n
- Sanitization: Content is parsed using strict regular expressions for epic and story headings, which limits the influence of arbitrary prose on the resulting status file.\n- [COMMAND_EXECUTION]: The skill executes local Python scripts to perform data processing tasks.\n
- Evidence: The skill uses
uv runto execute scripts like sprint_plan.py and platform-level scripts such as resolve_customization.py for workflow management.\n- [DYNAMIC_EXECUTION]: The main logic script uses the ruamel.yaml library to handle sprint status files.\n - Evidence: The script utilizes the round-trip loader (
typ=\"rt\") in sprint_plan.py to preserve human-written comments and formatting when updating the YAML status file.\n- [DYNAMIC_EXECUTION]: The skill supports user-defined workflow hooks.\n - Evidence: The SKILL.md instructions direct the agent to execute activation and completion steps defined in the customize.toml configuration, allowing for workflow extensions via project-specific instructions.
Audit Metadata