bmad-help
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes a local script using the command
uv run {project-root}/_bmad/scripts/resolve_config.py. This executes code within the project environment to resolve configuration settings. - [EXTERNAL_DOWNLOADS]: The skill fetches content from external URLs defined in the
output-locationcolumn of thebmad-help.csvfile when_metais present in the skill column. This content is used to answer user questions. - [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes data from external sources and project artifacts to generate responses and recommendations.
- Ingestion points: Local CSV manifest (
bmad-help.csv), remote documentation URLs, and project output artifacts. - Boundary markers: The instructions do not specify any delimiters or ignore-instructions for the external documentation content.
- Capability inventory: Execution of local scripts via
uvand steering the agent toward subsequent skill executions. - Sanitization: There is no evidence of sanitization or validation for the content retrieved from remote documentation URLs.
Audit Metadata