sprint-status

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from various project files which may contain untrusted content.
  • Ingestion points: The skill reads from production/sprints/*.md, production/sprint-status.yaml, and production/epics/**/story-*.md in SKILL.md.
  • Boundary markers: Absent. The instructions do not specify any delimiters or warnings to ignore embedded instructions within these data sources.
  • Capability inventory: The skill utilizes Bash (for specific script execution), Grep, Glob, and Read capabilities.
  • Sanitization: No sanitization or validation of the input content is performed before the model processes the data.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses platform-specific !bash syntax to execute commands at load time.
  • Evidence: The skill executes ${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh and ${CLAUDE_SKILL_DIR}/../../scripts/story-status.sh to initialize configuration and status reporting.
  • Context: These injections are used for benign internal project management tasks and do not involve user-controlled input or network operations at the time of execution.
  • [COMMAND_EXECUTION]: The skill invokes local shell scripts and tools to aggregate project data.
  • Evidence: It executes a grep command with a complex regular expression to scan for update timestamps across all story files in the production/epics/ directory.
  • Evidence: The skill calls local scripts yaml-helper.sh and story-status.sh as permitted by the frontmatter configuration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:51 PM
Security Audit — agent-trust-hub — sprint-status