skills/jeremylongshore/claude-code-plugins-plus-skills/backlog-grooming-assistant/Gen Agent Trust Hub
backlog-grooming-assistant
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE] (SAFE): No malicious patterns, obfuscation, or data exfiltration attempts were detected in the skill file. The content is restricted to documentation and metadata.
- [Indirect Prompt Injection] (LOW): The skill presents an attack surface for indirect prompt injection as it is designed to process external backlog data while having access to powerful tools like Bash. 1. Ingestion points: User-provided backlog items and enterprise workflow requests. 2. Boundary markers: Absent. 3. Capability inventory: Bash, Read, Write, Edit (as declared in allowed-tools). 4. Sanitization: Absent in the documentation provided.
Audit Metadata