bmad-deep-recon
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external web searches and user-provided research reports (as detailed in references/process.md and references/run.md).\n
- Ingestion points: The imports/ directory and data returned by web search MCP tools.\n
- Boundary markers: The skill implements a 'Research Firewall' described in SKILL.md and references/run.md, which ensures that research sub-agents receive only specific briefs without access to general project context.\n
- Capability inventory: The skill has the ability to write files to the research workspace and execute shell commands via uv run for management tasks.\n
- Sanitization: The scripts/recon_kit.py utility provides HTML escaping and scheme-based URL validation (restricting links to http/s) for generated artifacts.\n- [COMMAND_EXECUTION]: The skill executes local Python scripts (e.g., memlog.py, resolve_config.py, and recon_kit.py) using the uv run command. These scripts are utilized for structured logging, configuration resolution, and deterministic data processing within the project environment.\n- [EXTERNAL_DOWNLOADS]: The skill instructions (e.g., in types/academic-lit.md and customize.toml) involve querying external services and academic databases such as Google Scholar, Semantic Scholar, Tavily, and Perplexity. These references are part of the intended research functionality for information acquisition.
Audit Metadata