bmad-build
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill's bootstrap instruction in
SKILL.mdrequires the execution of a project-local script (_bmad/scripts/render_skill.py) using theuvtool. This is a controlled execution of a framework-specific component within the project's own directory. - [DYNAMIC_EXECUTION]: The workflow orchestrates the creation and execution of specialized, context-free subagents for coding and review tasks. These agents are directed by dynamically generated prompts based on the current project state and developer specifications.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an inherent attack surface by ingesting external user intent (e.g., story descriptions or issue links) to generate specifications. It mitigates this risk through several design patterns:
- Ingestion Points: User-provided intent prompts and external files processed in
step-01-clarify-and-route.md. - Boundary Markers: Uses
<frozen-after-approval>tags to delimit human-verified intent from agent-generated content. - Capability Inventory: Capabilities include file system writing, local script execution, and subagent orchestration.
- Sanitization: The planning process in
step-02-plan.mdacts as a distillation phase, and the skill explicitly instructs the agent to ignore any directives within the intent that attempt to bypass workflow steps.
Audit Metadata