bmad-prfaq
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local Python script using
uv runat{project-root}/_bmad/scripts/resolve_customization.py. This occurs during activation and at the terminal stage to handle configuration and post-completion logic. - [INDIRECT_PROMPT_INJECTION]: The skill utilizes sub-agents to ingest data from untrusted sources, creating a risk of indirect prompt injection.
- Ingestion points: The
Artifact Analyzersub-agent reads local project files from{planning_artifacts}and{project_knowledge}, while theWeb Researchersub-agent ingests content from external web searches. - Boundary markers: The sub-agent prompts do not define explicit boundary markers or instructions to ignore embedded commands within the ingested data.
- Capability inventory: The skill has the capability to write files to the project directory and execute a specific local script via
uv run. - Sanitization: No explicit sanitization or filtering of external content is performed before processing.
Audit Metadata