agile-sprint

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues were detected. The skill follows best practices for agile workflow automation and project documentation.
  • [DATA_EXPOSURE]: The skill operates on project-specific data (backlogs, epics, and retrospectives) to generate planning artifacts. All file operations are restricted to the local project structure (e.g., the planning/ directory), and no network exfiltration patterns were identified.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it ingests untrusted data from backlog items, epic descriptions, and user arguments. However, its capabilities are limited to generating markdown documentation and recommending next steps in the agile flow, which presents a negligible risk profile.
  • Ingestion points: $ARGUMENTS, Epic files, Retro files, and Backlog items.
  • Boundary markers: Absent; uses standard markdown headers.
  • Capability inventory: File writing to the planning/ directory.
  • Sanitization: Absent; relies on standard agent processing of project files.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 01:20 PM
Security Audit — agent-trust-hub — agile-sprint