bmad-advanced-elicitation

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests elicitation methods and their descriptions from external data files and uses them as direct instructions for the agent's refinement process.
  • Ingestion points: Data is loaded from assets/methods.csv and the workflow.additional_methods field in customize.toml (which can point to external JSON files via path resolution in pick_methods.py).
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat the method descriptions as non-executable text; the skill explicitly directs the agent to 'Use the method's description as its intent'.
  • Capability inventory: The skill has the capability to modify and replace the agent's recent conversation outputs, plans, and technical drafts based on the selected methods.
  • Sanitization: The skill does not implement validation or sanitization of the method descriptions or patterns loaded from the catalog.
  • [COMMAND_EXECUTION]: The skill instructions direct the agent to execute local Python scripts (pick_methods.py, resolve_customization.py, resolve_config.py) using uv run to manage its state and catalog. While these scripts are local to the skill or project, the execution flow involves building and running shell commands based on configuration values.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:08 AM
Security Audit — agent-trust-hub — bmad-advanced-elicitation