bmad-party-mode

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data to generate agent personas.
  • Ingestion points: In references/create-party.md, the skill is instructed to "distill from source data" such as spreadsheets, survey exports, and interview notes to create persona configurations. Additionally, SKILL.md describes loading facts from file:-prefixed paths/globs.
  • Boundary markers: The instructions do not specify the use of delimiters or clear "ignore embedded instructions" warnings when processing these external data sources.
  • Capability inventory: The skill possesses significant capabilities, including executing subprocesses via scripts/resolve_party.py, writing to configuration files via bmad-customize, and managing persistent memory via memlog.py.
  • Sanitization: There is no evidence of sanitization or strict schema validation for the distilled persona content before it is integrated into the instructions for subagents.
  • [COMMAND_EXECUTION]: The script scripts/resolve_party.py utilizes subprocess.run() to execute other Python scripts (resolve_config.py and resolve_customization.py). While it uses the safe pattern of passing arguments as a list (avoiding shell=True), this capability relies on the integrity of the {project-root} and {skill-root} paths provided by the environment.
  • [DYNAMIC_EXECUTION]: The configuration file customize.toml includes activation_steps_prepend and activation_steps_append fields. The instructions in SKILL.md direct the agent to "run each entry" in these arrays during activation. This allows the execution of arbitrary natural language instructions or tool calls defined within the configuration data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:08 AM
Security Audit — agent-trust-hub — bmad-party-mode