bmad-forge-idea

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute local utility scripts (e.g., resolve_customization.py, resolve_config.py, memlog.py) using uv run. These commands are parameterized by environment-specific placeholders such as {project-root} and {skill-root}.
  • [DYNAMIC_EXECUTION]: The resolve_personas.py script dynamically constructs and executes command lists to invoke other Python scripts using the current Python interpreter (sys.executable). It targets specific paths within the project's internal _bmad directory.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process user-supplied ideas and existing project files to provide feedback. It lacks explicit instruction-level delimiters or sanitization steps for handling potentially malicious content within these external inputs.
  • Ingestion points: User-provided subject ideas and goal descriptions; external project files and materials referenced during the session.
  • Boundary markers: None identified in the instructions for processing external project files.
  • Capability inventory: Local command execution via uv run and subprocess.run for logging, configuration, and persona resolution.
  • Sanitization: No specific sanitization or validation logic is applied to the content of ingested project files or user ideas before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:08 AM
Security Audit — agent-trust-hub — bmad-forge-idea