sprint-plan

Pass

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses dynamic context injection to execute ls production/sprints/ when loaded. This is used to discover existing sprint files and is considered a benign use of the feature.
  • [PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it ingests data from multiple project directories to generate plans.
  • Ingestion points: Reads files from production/milestones/, production/sprints/, design/gdd/, and production/risk-register/.
  • Boundary markers: None identified in the skill instructions.
  • Capability inventory: The skill has access to Write and Edit tools via the allowed-tools configuration.
  • Sanitization: No validation or sanitization of ingested content is performed before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 28, 2026, 12:11 PM
Security Audit — agent-trust-hub — sprint-plan