bmad-agent-analyst

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses uv run to execute a project-local script (_bmad/scripts/resolve_customization.py) during its activation phase. This script is responsible for merging configuration layers from various TOML files.
  • [INDIRECT_PROMPT_INJECTION]: The agent's persona, role, and principles are dynamically populated from external configuration files (customize.toml, config.yaml, and project-level overrides). This creates a surface where external data can influence the agent's core behavior.
  • Ingestion points: Data is pulled from {skill-root}/customize.toml, {project-root}/_bmad/custom/{skill-name}.toml, and {project-root}/_bmad/bmm/config.yaml.
  • Boundary markers: The skill does not employ explicit boundary markers or 'ignore' instructions when interpolating these values into its prompt.
  • Capability inventory: The skill can execute activation steps, invoke other registered skills (like bmad-deep-recon), and read project files.
  • Sanitization: There is no evidence of sanitization for the persona strings or facts loaded from the configuration files.
  • [DYNAMIC_EXECUTION]: The skill supports activation_steps_prepend and activation_steps_append arrays in its configuration. These allow the agent to execute a sequence of arbitrary instructions or tasks defined in the project's customization files before and after its standard greeting routine.
  • [DATA_EXPOSURE]: The skill includes a 'Persistent Facts' feature that allows it to load the contents of any file path prefixed with file: (e.g., file:{project-root}/docs/standards.md) into the agent's foundational context for the session.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:08 AM
Security Audit — agent-trust-hub — bmad-agent-analyst