scrum-master

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security risks were identified across the 12 files analyzed.
  • [COMMAND_EXECUTION]: The skill uses Python scripts (velocity_analyzer.py, sprint_health_scorer.py, retrospective_analyzer.py) to process JSON data. These scripts are provided within the skill package and use only standard library modules to perform calculations and text processing.
  • [DATA_EXFILTRATION]: There is no evidence of network activity or attempts to access sensitive files (such as SSH keys or cloud credentials). The scripts operate locally on the data provided through command-line arguments.
  • [PROMPT_INJECTION]: The instructions provided in SKILL.md are focused on agile coaching and process facilitation. They do not contain any instructions that attempt to bypass AI safety filters or override the agent's core behavior guidelines.
  • [REMOTE_CODE_EXECUTION]: No remote dependencies or external script downloads are utilized. All analysis is performed by scripts bundled with the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 08:17 AM
Security Audit — agent-trust-hub — scrum-master