bmad-agent-architect

Warn

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a Python script located within the project's working directory during activation. While this is a common pattern for developer tools, it carries inherent risk if the workspace is untrusted.
  • Evidence: In SKILL.md, Step 1 of the activation process runs the following command: uv run {project-root}/_bmad/scripts/resolve_customization.py --skill {skill-root} --project-root {project-root} --key agent. This execution relies on the integrity of the script provided within the {project-root}.
  • [INDIRECT_PROMPT_INJECTION]: The skill's persona, principles, and foundational facts are dynamically loaded from multiple configuration files within the project root, creating a large surface for indirect injection of malicious instructions.
  • Ingestion points: SKILL.md (Steps 1, 4, and 5) reads configuration from {project-root}/_bmad/custom/{skill-name}.toml, {project-root}/_bmad/custom/{skill-name}.user.toml, {project-root}/_bmad/bmm/config.yaml, and any files referenced in the persistent_facts array via the file: prefix.
  • Boundary markers: There are no explicit boundary markers or instructions to ignore embedded commands or instructions when processing these external project files.
  • Capability inventory: The agent has capabilities to execute shell commands (uv run), read project files, and perform actions based on a dynamic menu that can execute arbitrary prompts.
  • Sanitization: No sanitization or validation of the ingested configuration content is described; the agent is instructed to manually merge and adopt the values if the resolution script fails.
  • [DYNAMIC_EXECUTION]: The skill is instructed to execute a sequence of 'activation steps' defined in external configuration files, which could lead to the execution of arbitrary logic or instructions.
  • Evidence: SKILL.md contains specific steps to "Execute each entry in {agent.activation_steps_prepend}" (Step 2) and "Execute each entry in {agent.activation_steps_append}" (Step 7). Because these steps are defined in the mutable {project-root} configuration files, an attacker could inject instructions into these lists that the agent will blindly follow upon activation.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 20, 2026, 07:08 AM
Security Audit — agent-trust-hub — bmad-agent-architect