bmad-agent-architect
Warn
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a Python script located within the project's working directory during activation. While this is a common pattern for developer tools, it carries inherent risk if the workspace is untrusted.
- Evidence: In
SKILL.md, Step 1 of the activation process runs the following command:uv run {project-root}/_bmad/scripts/resolve_customization.py --skill {skill-root} --project-root {project-root} --key agent. This execution relies on the integrity of the script provided within the{project-root}. - [INDIRECT_PROMPT_INJECTION]: The skill's persona, principles, and foundational facts are dynamically loaded from multiple configuration files within the project root, creating a large surface for indirect injection of malicious instructions.
- Ingestion points:
SKILL.md(Steps 1, 4, and 5) reads configuration from{project-root}/_bmad/custom/{skill-name}.toml,{project-root}/_bmad/custom/{skill-name}.user.toml,{project-root}/_bmad/bmm/config.yaml, and any files referenced in thepersistent_factsarray via thefile:prefix. - Boundary markers: There are no explicit boundary markers or instructions to ignore embedded commands or instructions when processing these external project files.
- Capability inventory: The agent has capabilities to execute shell commands (
uv run), read project files, and perform actions based on a dynamic menu that can execute arbitrary prompts. - Sanitization: No sanitization or validation of the ingested configuration content is described; the agent is instructed to manually merge and adopt the values if the resolution script fails.
- [DYNAMIC_EXECUTION]: The skill is instructed to execute a sequence of 'activation steps' defined in external configuration files, which could lead to the execution of arbitrary logic or instructions.
- Evidence:
SKILL.mdcontains specific steps to "Execute each entry in{agent.activation_steps_prepend}" (Step 2) and "Execute each entry in{agent.activation_steps_append}" (Step 7). Because these steps are defined in the mutable{project-root}configuration files, an attacker could inject instructions into these lists that the agent will blindly follow upon activation.
Audit Metadata