bmad-correct-course
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local Python script using
uv runat the start and end of the workflow. - Evidence: Step 1 and Step 6 in
SKILL.mdinvoke{project-root}/_bmad/scripts/resolve_customization.pyto handle configuration merging and finalization tasks. - [INDIRECT_PROMPT_INJECTION]: The skill ingests multiple external project documents which could potentially contain malicious instructions intended to influence the agent's behavior.
- Ingestion points: The skill performs a
FULL_LOADof files matching patterns for PRD, Epics, Architecture, UX Design, and Specifications, as well as theAGENTS.mdfile (found inSKILL.mdunder Input Files and Execution sections). - Boundary markers: The instructions do not define explicit delimiters or instructions to ignore embedded prompts within the loaded artifacts.
- Capability inventory: The agent has the ability to execute local scripts via
uv runand write the final proposal to a file path in the project directory. - Sanitization: There is no evidence of sanitization, validation, or filtering of the content read from the project artifacts before processing.
- [DYNAMIC_EXECUTION]: The skill dynamically loads and follows instructions provided in the configuration files.
- Evidence: In Step 6 of
SKILL.md, the agent is instructed to resolve theworkflow.on_completekey from the customization files and "follow it as the final terminal instruction before exiting." This allows for the execution of arbitrary instructions defined in external configuration files (customize.tomlor user/team overrides).
Audit Metadata