bmad-agent-dev

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a Python script (resolve_customization.py) via the uv package manager during its activation sequence (Step 1). While the script is located within the project's own directory structure (_bmad/scripts/), this represents an automated shell execution triggered by loading the skill.
  • [INDIRECT_PROMPT_INJECTION]: The skill dynamically builds its persona, context, and operational steps by merging data from multiple external configuration files found within the project directory.
  • Ingestion points: The skill reads {project-root}/_bmad/custom/{skill-name}.toml, {project-root}/_bmad/custom/{skill-name}.user.toml, and {project-root}/_bmad/bmm/config.yaml to populate its persona (role, identity, principles) and activation steps.
  • Boundary markers: Absent. Instructions loaded from these files are integrated directly into the agent's core operating instructions without delimiters or warnings to ignore embedded commands.
  • Capability inventory: The agent has the ability to invoke other skills (e.g., bmad-build, bmad-code-review) and execute arbitrary prompt text defined in the agent.menu configuration.
  • Sanitization: None. The skill is explicitly instructed to "Fully embody this persona" and "Adopt the customized persona on top," meaning it will follow any instructions or behavioral overrides found in the project's configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:07 AM
Security Audit — agent-trust-hub — bmad-agent-dev