bmad-brainstorming

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates entirely using local resources. The primary logic is contained in scripts/brain.py, which manages a technique library stored in a local CSV file. It does not perform unauthorized network requests or download external code.
  • [COMMAND_EXECUTION]: The skill utilizes the uv run command to execute specific Python scripts for configuration resolution (resolve_customization.py), session persistence (memlog.py), and library management (brain.py). These scripts are either provided within the skill or are part of the host environment's verified BMad framework.
  • [DATA_EXFILTRATION]: The skill includes a feature for 'external handoffs' (e.g., to Confluence or Notion). This is a user-configured platform feature defined in customize.toml and does not represent an automated or hidden exfiltration attempt by the skill author.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied brainstorming topics and ideas to generate final artifacts (HTML and Markdown). While this creates a theoretical surface for injection if user content is not sanitized, the internal library management script (brain.py) uses standard HTML escaping for its generated selection page, and artifact generation is handled by scoped subagents following a structured workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:08 AM
Security Audit — agent-trust-hub — bmad-brainstorming