bmad-qa-generate-e2e-tests
Warn
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is configured to execute a local Python script
{project-root}/_bmad/scripts/resolve_customization.pyusing theuv runcommand during both the activation and completion phases. - [COMMAND_EXECUTION]: The agent is instructed to run the project's specific test commands (e.g.,
npm test,pytest) to verify the functionality of the generated tests in Step 4 of the execution phase. - [DYNAMIC_EXECUTION]: The workflow dynamically loads and executes instructions from fields such as
activation_steps_prepend,activation_steps_append, andon_complete. These instructions are merged from multiple external configuration files, including project-level (_bmad/custom/{skill-name}.toml) and user-level (_bmad/custom/{skill-name}.user.toml) overrides, which allows for arbitrary instruction injection. - [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection due to its processing of untrusted data combined with powerful execution capabilities.
- Ingestion points: The skill reads
package.json, project source code files,config.yaml, and external TOML configuration overrides. It also performs online searches to recommend testing frameworks. - Boundary markers: There are no explicit delimiters or instructions provided to the agent to distinguish between data and instructions when processing project files.
- Capability inventory: The skill has the capability to execute shell commands via
uv runand standard project test runners. - Sanitization: No validation or sanitization is performed on the content of the project files or external configurations before they are used to influence the agent's behavior or execution steps.
Audit Metadata