bmad-agent-pm
Fail
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: HIGHCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions direct the agent to run a Python script via
uv runduring activation. Furthermore, it commands the agent to execute any strings found in theactivation_steps_prependandactivation_steps_appendarrays. Because these arrays are populated from configuration files that can be overridden at the project or user level (e.g.,{project-root}/_bmad/custom/bmad-agent-pm.toml), this allows for the execution of arbitrary shell commands in the project environment. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the project root that could contain malicious instructions.
- Ingestion points: The agent loads 'persistent facts' from strings and files (including those matching glob patterns) defined in
customize.tomland its project-level overrides. It also loads configuration from{project-root}/_bmad/bmm/config.yamland resolves user-specific artifacts. - Boundary markers: There are no delimiters or instructions to treat the loaded file content as untrusted data, increasing the risk that the agent will follow instructions embedded within those files.
- Capability inventory: The skill has access to shell execution via
uv runand the activation step mechanism, as well as the ability to invoke multiple other skills likebmad-prd. - Sanitization: No sanitization or validation of the content loaded from project files is performed before it is added to the agent's context.
- [DYNAMIC_EXECUTION]: The agent is instructed to execute prompts and commands that are dynamically resolved from configuration files at runtime, including values from
agent.menuand theagent.activation_stepsarrays. This pattern allows the behavior of the agent to be fundamentally altered by the content of local project files.
Recommendations
- AI detected serious security threats
Audit Metadata