bmad-advanced-elicitation
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests elicitation methods and their descriptions from external data files and uses them as direct instructions for the agent's refinement process.
- Ingestion points: Data is loaded from
assets/methods.csvand theworkflow.additional_methodsfield incustomize.toml(which can point to external JSON files via path resolution inpick_methods.py). - Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat the method descriptions as non-executable text; the skill explicitly directs the agent to 'Use the method's description as its intent'.
- Capability inventory: The skill has the capability to modify and replace the agent's recent conversation outputs, plans, and technical drafts based on the selected methods.
- Sanitization: The skill does not implement validation or sanitization of the method descriptions or patterns loaded from the catalog.
- [COMMAND_EXECUTION]: The skill instructions direct the agent to execute local Python scripts (
pick_methods.py,resolve_customization.py,resolve_config.py) usinguv runto manage its state and catalog. While these scripts are local to the skill or project, the execution flow involves building and running shell commands based on configuration values.
Audit Metadata