sprint-status
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from various project files which may contain untrusted content.
- Ingestion points: The skill reads from
production/sprints/*.md,production/sprint-status.yaml, andproduction/epics/**/story-*.mdinSKILL.md. - Boundary markers: Absent. The instructions do not specify any delimiters or warnings to ignore embedded instructions within these data sources.
- Capability inventory: The skill utilizes
Bash(for specific script execution),Grep,Glob, andReadcapabilities. - Sanitization: No sanitization or validation of the input content is performed before the model processes the data.
- [DYNAMIC_CONTEXT_INJECTION]: The skill uses platform-specific
!bashsyntax to execute commands at load time. - Evidence: The skill executes
${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.shand${CLAUDE_SKILL_DIR}/../../scripts/story-status.shto initialize configuration and status reporting. - Context: These injections are used for benign internal project management tasks and do not involve user-controlled input or network operations at the time of execution.
- [COMMAND_EXECUTION]: The skill invokes local shell scripts and tools to aggregate project data.
- Evidence: It executes a
grepcommand with a complex regular expression to scan for update timestamps across all story files in theproduction/epics/directory. - Evidence: The skill calls local scripts
yaml-helper.shandstory-status.shas permitted by the frontmatter configuration.
Audit Metadata