bmad-build-auto
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The workflow in
step-03-implement.mdexplicitly instructs the agent to execute shell commands found in the## Verificationsection of a generated specification file. This allows for the execution of arbitrary shell commands that the agent itself planned during earlier steps. - [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface where untrusted data from external planning artifacts (such as PRDs, architecture documents, or UX designs) is processed to generate implementation specs. Malicious instructions in these artifacts could potentially influence the commands the agent generates and subsequently executes.
- Ingestion points:
step-01-clarify-and-route.mdingests diverse planning artifacts and epic contexts into the agent's environment. - Boundary markers: The skill uses delimiters like
<intent-contract>and specific section filtering to attempt to isolate untrusted content, though these are not absolute safeguards. - Capability inventory: The agent has permissions to write files, execute shell commands, and perform Git operations.
- Sanitization: There is no explicit sanitization found in the workflow for commands extracted from the generated specs before execution.
- [DYNAMIC_EXECUTION]: The entry point in
SKILL.mdexecutes a Python script located within the project repository (_bmad/scripts/render_skill.py) usinguv run. This means the skill's operational logic is partially determined by the contents of the repository being worked on.
Audit Metadata