bmad-forge-idea
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute local utility scripts (e.g.,
resolve_customization.py,resolve_config.py,memlog.py) usinguv run. These commands are parameterized by environment-specific placeholders such as{project-root}and{skill-root}. - [DYNAMIC_EXECUTION]: The
resolve_personas.pyscript dynamically constructs and executes command lists to invoke other Python scripts using the current Python interpreter (sys.executable). It targets specific paths within the project's internal_bmaddirectory. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process user-supplied ideas and existing project files to provide feedback. It lacks explicit instruction-level delimiters or sanitization steps for handling potentially malicious content within these external inputs.
- Ingestion points: User-provided subject ideas and goal descriptions; external project files and materials referenced during the session.
- Boundary markers: None identified in the instructions for processing external project files.
- Capability inventory: Local command execution via
uv runandsubprocess.runfor logging, configuration, and persona resolution. - Sanitization: No specific sanitization or validation logic is applied to the content of ingested project files or user ideas before they are processed by the agent.
Audit Metadata