bmad-agent-dev
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a Python script (
resolve_customization.py) via theuvpackage manager during its activation sequence (Step 1). While the script is located within the project's own directory structure (_bmad/scripts/), this represents an automated shell execution triggered by loading the skill. - [INDIRECT_PROMPT_INJECTION]: The skill dynamically builds its persona, context, and operational steps by merging data from multiple external configuration files found within the project directory.
- Ingestion points: The skill reads
{project-root}/_bmad/custom/{skill-name}.toml,{project-root}/_bmad/custom/{skill-name}.user.toml, and{project-root}/_bmad/bmm/config.yamlto populate its persona (role,identity,principles) and activation steps. - Boundary markers: Absent. Instructions loaded from these files are integrated directly into the agent's core operating instructions without delimiters or warnings to ignore embedded commands.
- Capability inventory: The agent has the ability to invoke other skills (e.g.,
bmad-build,bmad-code-review) and execute arbitrary prompt text defined in theagent.menuconfiguration. - Sanitization: None. The skill is explicitly instructed to "Fully embody this persona" and "Adopt the customized persona on top," meaning it will follow any instructions or behavioral overrides found in the project's configuration files.
Audit Metadata