bmad-retrospective
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from project story files, sprint status YAML, and session logs, creating a potential surface for indirect prompt injection.\n
- Ingestion points: Ingests
session logs,SPEC.md,stories.yaml, andsprint-status.yamlduring Phases 1 and 2.\n - Boundary markers: Includes strong instructions to discard claims that lack source references and to verify sub-agent findings against primary sources (commits, files, specs) before routing them as action items.\n
- Capability inventory: Capable of executing
gitcommands, invoking external skills (bmad-review,bmad-party-mode), and performing atomic writes to local project files.\n - Sanitization: Requires all findings to be provenance-linked and verified against ground-truth artifacts.\n- [COMMAND_EXECUTION]: The skill executes shell commands, primarily the
gitbinary, to collect change evidence.\n - Evidence:
scripts/git_evidence.pyusessubprocess.runto callgit log. The script includes custom argument parsing and validation to prevent injection of malicious flags via user-supplied revision ranges.\n- [DYNAMIC_EXECUTION]: The skill executes project-resident scripts during activation to resolve workflow customization settings.\n - Evidence:
SKILL.mdinstructs the agent to run{project-root}/_bmad/scripts/resolve_customization.py. This capability relies on the integrity of the scripts resident in the project's repository environment.
Audit Metadata