bmad-qa-generate-e2e-tests

Warn

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is configured to execute a local Python script {project-root}/_bmad/scripts/resolve_customization.py using the uv run command during both the activation and completion phases.
  • [COMMAND_EXECUTION]: The agent is instructed to run the project's specific test commands (e.g., npm test, pytest) to verify the functionality of the generated tests in Step 4 of the execution phase.
  • [DYNAMIC_EXECUTION]: The workflow dynamically loads and executes instructions from fields such as activation_steps_prepend, activation_steps_append, and on_complete. These instructions are merged from multiple external configuration files, including project-level (_bmad/custom/{skill-name}.toml) and user-level (_bmad/custom/{skill-name}.user.toml) overrides, which allows for arbitrary instruction injection.
  • [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection due to its processing of untrusted data combined with powerful execution capabilities.
  • Ingestion points: The skill reads package.json, project source code files, config.yaml, and external TOML configuration overrides. It also performs online searches to recommend testing frameworks.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to distinguish between data and instructions when processing project files.
  • Capability inventory: The skill has the capability to execute shell commands via uv run and standard project test runners.
  • Sanitization: No validation or sanitization is performed on the content of the project files or external configurations before they are used to influence the agent's behavior or execution steps.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 20, 2026, 07:08 AM
Security Audit — agent-trust-hub — bmad-qa-generate-e2e-tests