bmad-code-review

Fail

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: HIGHCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a Python script located at {project-root}/_bmad/scripts/resolve_customization.py using the uv run command in SKILL.md and step-04-present.md. Because {project-root} refers to the repository being reviewed, a malicious repository could include a script at this path to execute arbitrary commands with the agent's privileges.
  • [COMMAND_EXECUTION]: The workflow constructs shell commands (e.g., git diff, gh pr view) using branch names, PR references, and file paths extracted from the conversation context. If these inputs are not properly sanitized before being interpolated into shell commands, it could lead to shell command injection.
  • [DYNAMIC_EXECUTION]: The skill dynamically resolves and runs scripts from computed paths within the project workspace, which facilitates the execution of unverified code not bundled with the skill itself.
  • [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests and processes untrusted data from git diffs and commit messages.
  • Ingestion points: step-01-gather-context.md (capturing git diff and git log output).
  • Boundary markers: While prompts for subagents use labels like CONTENT: and Diff:, the input data is not sanitized or escaped.
  • Capability inventory: The parent agent has access to shell commands (git, gh, uv) and can write to project files.
  • Sanitization: No sanitization is performed on the ingested narrative or code changes before they are passed to subagents for analysis.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 20, 2026, 07:08 AM
Security Audit — agent-trust-hub — bmad-code-review