bmad-customize

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes uv run to execute local helper scripts (list_customizable_skills.py and resolve_customization.py). These scripts are used for discovering customizable components within the user's project and verifying that customization files are correctly formatted and placed.
  • [COMMAND_EXECUTION]: The included test suite in scripts/tests/test_list_customizable_skills.py uses subprocess.run to call the Python interpreter for CLI verification. This is standard practice for unit testing and is confined to the development/test environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources by reading SKILL.md descriptions and customize.toml definitions from other installed skills. While this creates a potential surface for indirect prompt injection if a user has installed a malicious third-party skill, the impact is minimized as the data is used strictly for surfacing configuration options and metadata to the user within a localized workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:07 AM
Security Audit — agent-trust-hub — bmad-customize