bmad-project-context
Warn
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: Upon activation, the skill executes Python scripts located in the project's directory (
_bmad/scripts/resolve_customization.pyand_bmad/scripts/resolve_config.py) using theuv runcommand. This represents the execution of code residing in the target environment that is external to the skill package. - [DYNAMIC_EXECUTION]: The workflow allows for the execution of arbitrary shell commands defined in configuration fields (
activation_steps_prependandactivation_steps_append) found incustomize.tomlor its overrides. This provides a mechanism for running arbitrary logic at runtime based on external configuration. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and analyzes various untrusted files from the target repository, creating a potential vector for indirect prompt injection.
- Ingestion points: The skill reads
AGENTS.md, build manifests (package.json,Makefile,pyproject.toml), contribution guides, and CI configurations from the{project-root}(SKILL.md, Step 1 and 3). - Boundary markers: While the skill uses HTML-style comment markers (
<!-- bmad:context -->) for its output, it lacks explicit instructions to ignore embedded prompts within the ingested data during its analysis phase (template.md). - Capability inventory: The agent can execute shell commands (via
uv runand configuration hooks) and write changes back to the repository (SKILL.md, On Activation and Step 5). - Sanitization: No sanitization, validation, or filtering of the content ingested from the repository is described (SKILL.md).
Audit Metadata