planning-sprints
Audited by Socket on Mar 9, 2026
1 alert found:
Obfuscated FileThe skill's described capabilities (sprint planning, backlog analysis, velocity/capacity tracking, sprint goal definition, progress monitoring, and retrospectives) are coherent with its stated purpose. The data flows involve standard developer tooling (gh CLI, local templates/scripts) and produce artifacts (plan docs, board updates) that align with sprint planning workflows. There are no evident malicious data exfiltration paths or unverifiable binaries. Credential exposure risks are limited to relying on pre-authenticated gh CLI usage; explicit secrets are not shown. Overall risk is low to moderate, primarily related to credential handling and autonomous delegation aspects rather than core functionality.