bmad-architecture
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes local utility scripts (
memlog.py,resolve_customization.py,resolve_config.py, andlint_spine.py) using theuvtool to manage the workflow lifecycle, resolve configuration settings, and perform mechanical linting of the generated architecture files as specified inSKILL.md. - [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface by design, as it is intended to process and summarize external, untrusted content like project specifications and codebases.
- Ingestion points: Processes specifications (
SPEC.md), raw project ideas, and existing codebase content to derive architectural invariants. - Boundary markers: The process uses a dedicated append-only
.memlog.mdfile and template-based distillation to separate input from internal decision logic, but lacks explicit boundary instructions to disregard malicious prompts embedded in the processed data. - Capability inventory: The skill executes local Python scripts via
uv runand writes toARCHITECTURE-SPINE.mdand.memlog.md(SKILL.md). - Sanitization: The instructions do not define specific sanitization or filtering of external content before it is processed by the agent.
Audit Metadata