bmad-correct-course

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local Python script using uv run at the start and end of the workflow.
  • Evidence: Step 1 and Step 6 in SKILL.md invoke {project-root}/_bmad/scripts/resolve_customization.py to handle configuration merging and finalization tasks.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests multiple external project documents which could potentially contain malicious instructions intended to influence the agent's behavior.
  • Ingestion points: The skill performs a FULL_LOAD of files matching patterns for PRD, Epics, Architecture, UX Design, and Specifications, as well as the AGENTS.md file (found in SKILL.md under Input Files and Execution sections).
  • Boundary markers: The instructions do not define explicit delimiters or instructions to ignore embedded prompts within the loaded artifacts.
  • Capability inventory: The agent has the ability to execute local scripts via uv run and write the final proposal to a file path in the project directory.
  • Sanitization: There is no evidence of sanitization, validation, or filtering of the content read from the project artifacts before processing.
  • [DYNAMIC_EXECUTION]: The skill dynamically loads and follows instructions provided in the configuration files.
  • Evidence: In Step 6 of SKILL.md, the agent is instructed to resolve the workflow.on_complete key from the customization files and "follow it as the final terminal instruction before exiting." This allows for the execution of arbitrary instructions defined in external configuration files (customize.toml or user/team overrides).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:07 AM
Security Audit — agent-trust-hub — bmad-correct-course