retrospective
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the dynamic context injection pattern (
!command) to execute a local shell script (yaml-helper.sh) at skill load time. This is used to resolve automation configuration from the project environment. While this feature executes shell commands automatically, the command used is benign and localized to the project's helper scripts. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from various project artifacts, including sprint plans, status YAML files, and source code (via TODO/FIXME scanning). This constitutes an attack surface for indirect prompt injection if these files contain malicious instructions. However, the skill's highly structured task of generating a technical report significantly mitigates the risk of the agent obeying embedded commands.
- [COMMAND_EXECUTION]: The skill executes
git logusing the Bash tool to analyze commit activity during the sprint period. This is a standard and expected operation for a software development lifecycle (SDLC) agent performing retrospective analysis.
Audit Metadata