bmad-architecture

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security concerns were identified. The skill adheres to its stated purpose of architectural planning and document generation.
  • [COMMAND_EXECUTION]: The skill executes local bash scripts (nfr-checklist.sh and validate-architecture.sh) to provide checklists and perform keyword-based validation of generated markdown files. These scripts use standard utilities like grep and cat and do not perform any dangerous operations.
  • [EXTERNAL_DOWNLOADS]: The skill is configured to use WebSearch and WebFetch for researching technology maturity during the design phase, which is consistent with the architect persona. It does not involve the automated downloading or execution of untrusted external software.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 12:30 PM
Security Audit — agent-trust-hub — bmad-architecture