sprint-plan

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from project story files, which could contain malicious instructions designed to influence the agent's behavior during planning.
  • Ingestion points: Reads story content and metadata from production/epics/**/story-*.md (Phase 1, Step 3).
  • Boundary markers: None. Story content is interpolated into the sprint plan and status YAML without delimiters or safety warnings.
  • Capability inventory: The skill has the ability to write files, edit configuration (project.yaml), execute shell commands, and delegate tasks to sub-agents.
  • Sanitization: No evidence of sanitization for the data read from story files.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the !command`` syntax to execute shell commands automatically when the skill is loaded.
  • Evidence: Found !bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config ... and `!`ls production/sprints/ ... in SKILL.md.
  • Usage: These commands are used to resolve configuration settings and check the filesystem state to inform the agent's initial context. While the commands themselves (ls, local script) are benign, this pattern represents a dynamic execution vector.
  • [COMMAND_EXECUTION]: The skill executes shell commands via the Bash tool and load-time injections.
  • Evidence: The skill is configured with a restricted Bash tool to run a local configuration helper script.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:52 PM
Security Audit — agent-trust-hub — sprint-plan