Scrum Master

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill logic is entirely consistent with its described role. It performs standard agile ceremonies like sprint planning and story breakdown using local context and tools. No obfuscation, remote code execution, or unauthorized data access patterns were found.
  • [PROMPT_INJECTION]: The skill ingests external project documentation (PRDs, technical specifications) which is a potential surface for indirect prompt injection. The risk is considered negligible as the skill's capabilities are restricted to documentation and planning workflows. Ingestion points: Reads PRD and technical specification files. Boundary markers: None explicitly stated in this skill file. Capability inventory: Reading local project files and writing data via task-tracking tools. Sanitization: No specific input validation or sanitization is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 04:49 PM
Security Audit — agent-trust-hub — Scrum Master