bmad-create-epics-and-stories
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using the
uv runutility to resolve customization settings and perform post-completion tasks. This occurs during the initial activation inSKILL.mdand the final phase instep-04-final-validation.md. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes content from external files such as
PRD.md,Architecture.md, and UX design documents. These files are controlled by the user or external contributors and could contain adversarial instructions that influence the agent's behavior. - Ingestion points:
step-01-validate-prerequisites.mdreads project requirements and architecture files to extract functional and non-functional requirements. - Boundary markers: The skill does not use explicit delimiters or instructions to ignore potential prompts within the ingested requirement text.
- Capability inventory: The agent has the ability to write to the local filesystem (
{planning_artifacts}/epics.md) and execute shell commands (uv run). - Sanitization: No sanitization or validation logic is applied to the extracted requirements before they are incorporated into the prompt context.
- [DYNAMIC_EXECUTION]: The skill's activation process allows for the execution of arbitrary commands or steps defined in
activation_steps_prependandactivation_steps_appendarrays within customization files. This allows the skill's behavior to be dynamically extended by local configuration files.
Audit Metadata