bmad-agent-analyst
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
uv runto execute a project-local script (_bmad/scripts/resolve_customization.py) during its activation phase. This script is responsible for merging configuration layers from various TOML files. - [INDIRECT_PROMPT_INJECTION]: The agent's persona, role, and principles are dynamically populated from external configuration files (
customize.toml,config.yaml, and project-level overrides). This creates a surface where external data can influence the agent's core behavior. - Ingestion points: Data is pulled from
{skill-root}/customize.toml,{project-root}/_bmad/custom/{skill-name}.toml, and{project-root}/_bmad/bmm/config.yaml. - Boundary markers: The skill does not employ explicit boundary markers or 'ignore' instructions when interpolating these values into its prompt.
- Capability inventory: The skill can execute activation steps, invoke other registered skills (like
bmad-deep-recon), and read project files. - Sanitization: There is no evidence of sanitization for the persona strings or facts loaded from the configuration files.
- [DYNAMIC_EXECUTION]: The skill supports
activation_steps_prependandactivation_steps_appendarrays in its configuration. These allow the agent to execute a sequence of arbitrary instructions or tasks defined in the project's customization files before and after its standard greeting routine. - [DATA_EXPOSURE]: The skill includes a 'Persistent Facts' feature that allows it to load the contents of any file path prefixed with
file:(e.g.,file:{project-root}/docs/standards.md) into the agent's foundational context for the session.
Audit Metadata