bmad-create-epics-and-stories

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using the uv run utility to resolve customization settings and perform post-completion tasks. This occurs during the initial activation in SKILL.md and the final phase in step-04-final-validation.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes content from external files such as PRD.md, Architecture.md, and UX design documents. These files are controlled by the user or external contributors and could contain adversarial instructions that influence the agent's behavior.
  • Ingestion points: step-01-validate-prerequisites.md reads project requirements and architecture files to extract functional and non-functional requirements.
  • Boundary markers: The skill does not use explicit delimiters or instructions to ignore potential prompts within the ingested requirement text.
  • Capability inventory: The agent has the ability to write to the local filesystem ({planning_artifacts}/epics.md) and execute shell commands (uv run).
  • Sanitization: No sanitization or validation logic is applied to the extracted requirements before they are incorporated into the prompt context.
  • [DYNAMIC_EXECUTION]: The skill's activation process allows for the execution of arbitrary commands or steps defined in activation_steps_prepend and activation_steps_append arrays within customization files. This allows the skill's behavior to be dynamically extended by local configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:08 AM
Security Audit — agent-trust-hub — bmad-create-epics-and-stories