bmad-build-auto

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The workflow in step-03-implement.md explicitly instructs the agent to execute shell commands found in the ## Verification section of a generated specification file. This allows for the execution of arbitrary shell commands that the agent itself planned during earlier steps.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface where untrusted data from external planning artifacts (such as PRDs, architecture documents, or UX designs) is processed to generate implementation specs. Malicious instructions in these artifacts could potentially influence the commands the agent generates and subsequently executes.
  • Ingestion points: step-01-clarify-and-route.md ingests diverse planning artifacts and epic contexts into the agent's environment.
  • Boundary markers: The skill uses delimiters like <intent-contract> and specific section filtering to attempt to isolate untrusted content, though these are not absolute safeguards.
  • Capability inventory: The agent has permissions to write files, execute shell commands, and perform Git operations.
  • Sanitization: There is no explicit sanitization found in the workflow for commands extracted from the generated specs before execution.
  • [DYNAMIC_EXECUTION]: The entry point in SKILL.md executes a Python script located within the project repository (_bmad/scripts/render_skill.py) using uv run. This means the skill's operational logic is partially determined by the contents of the repository being worked on.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:08 AM
Security Audit — agent-trust-hub — bmad-build-auto