bmad-retrospective

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from project story files, sprint status YAML, and session logs, creating a potential surface for indirect prompt injection.\n
  • Ingestion points: Ingests session logs, SPEC.md, stories.yaml, and sprint-status.yaml during Phases 1 and 2.\n
  • Boundary markers: Includes strong instructions to discard claims that lack source references and to verify sub-agent findings against primary sources (commits, files, specs) before routing them as action items.\n
  • Capability inventory: Capable of executing git commands, invoking external skills (bmad-review, bmad-party-mode), and performing atomic writes to local project files.\n
  • Sanitization: Requires all findings to be provenance-linked and verified against ground-truth artifacts.\n- [COMMAND_EXECUTION]: The skill executes shell commands, primarily the git binary, to collect change evidence.\n
  • Evidence: scripts/git_evidence.py uses subprocess.run to call git log. The script includes custom argument parsing and validation to prevent injection of malicious flags via user-supplied revision ranges.\n- [DYNAMIC_EXECUTION]: The skill executes project-resident scripts during activation to resolve workflow customization settings.\n
  • Evidence: SKILL.md instructs the agent to run {project-root}/_bmad/scripts/resolve_customization.py. This capability relies on the integrity of the scripts resident in the project's repository environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:08 AM
Security Audit — agent-trust-hub — bmad-retrospective