bmad-project-context

Warn

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: Upon activation, the skill executes Python scripts located in the project's directory (_bmad/scripts/resolve_customization.py and _bmad/scripts/resolve_config.py) using the uv run command. This represents the execution of code residing in the target environment that is external to the skill package.
  • [DYNAMIC_EXECUTION]: The workflow allows for the execution of arbitrary shell commands defined in configuration fields (activation_steps_prepend and activation_steps_append) found in customize.toml or its overrides. This provides a mechanism for running arbitrary logic at runtime based on external configuration.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and analyzes various untrusted files from the target repository, creating a potential vector for indirect prompt injection.
  • Ingestion points: The skill reads AGENTS.md, build manifests (package.json, Makefile, pyproject.toml), contribution guides, and CI configurations from the {project-root} (SKILL.md, Step 1 and 3).
  • Boundary markers: While the skill uses HTML-style comment markers (<!-- bmad:context -->) for its output, it lacks explicit instructions to ignore embedded prompts within the ingested data during its analysis phase (template.md).
  • Capability inventory: The agent can execute shell commands (via uv run and configuration hooks) and write changes back to the repository (SKILL.md, On Activation and Step 5).
  • Sanitization: No sanitization, validation, or filtering of the content ingested from the repository is described (SKILL.md).
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 20, 2026, 07:08 AM
Security Audit — agent-trust-hub — bmad-project-context