bmad-agent-pm

Fail

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: HIGHCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions direct the agent to run a Python script via uv run during activation. Furthermore, it commands the agent to execute any strings found in the activation_steps_prepend and activation_steps_append arrays. Because these arrays are populated from configuration files that can be overridden at the project or user level (e.g., {project-root}/_bmad/custom/bmad-agent-pm.toml), this allows for the execution of arbitrary shell commands in the project environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the project root that could contain malicious instructions.
  • Ingestion points: The agent loads 'persistent facts' from strings and files (including those matching glob patterns) defined in customize.toml and its project-level overrides. It also loads configuration from {project-root}/_bmad/bmm/config.yaml and resolves user-specific artifacts.
  • Boundary markers: There are no delimiters or instructions to treat the loaded file content as untrusted data, increasing the risk that the agent will follow instructions embedded within those files.
  • Capability inventory: The skill has access to shell execution via uv run and the activation step mechanism, as well as the ability to invoke multiple other skills like bmad-prd.
  • Sanitization: No sanitization or validation of the content loaded from project files is performed before it is added to the agent's context.
  • [DYNAMIC_EXECUTION]: The agent is instructed to execute prompts and commands that are dynamically resolved from configuration files at runtime, including values from agent.menu and the agent.activation_steps arrays. This pattern allows the behavior of the agent to be fundamentally altered by the content of local project files.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 20, 2026, 07:08 AM
Security Audit — agent-trust-hub — bmad-agent-pm