bmad-architecture

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes local utility scripts (memlog.py, resolve_customization.py, resolve_config.py, and lint_spine.py) using the uv tool to manage the workflow lifecycle, resolve configuration settings, and perform mechanical linting of the generated architecture files as specified in SKILL.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface by design, as it is intended to process and summarize external, untrusted content like project specifications and codebases.
  • Ingestion points: Processes specifications (SPEC.md), raw project ideas, and existing codebase content to derive architectural invariants.
  • Boundary markers: The process uses a dedicated append-only .memlog.md file and template-based distillation to separate input from internal decision logic, but lacks explicit boundary instructions to disregard malicious prompts embedded in the processed data.
  • Capability inventory: The skill executes local Python scripts via uv run and writes to ARCHITECTURE-SPINE.md and .memlog.md (SKILL.md).
  • Sanitization: The instructions do not define specific sanitization or filtering of external content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:08 AM
Security Audit — agent-trust-hub — bmad-architecture