bmad-review

Warn

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a Python script from the project root directory: uv run {project-root}/_bmad/scripts/resolve_customization.py. This presents a security risk if the repository being reviewed contains a malicious script at that path designed to exploit the agent during the review process.\n- [DYNAMIC_EXECUTION]: The skill executes "literal instructions" defined in configuration fields activation_steps_prepend, activation_steps_append, and on_complete. These fields are loaded from customize.toml and can be overridden by project-specific configuration files (e.g., {project-root}/_bmad/custom/bmad-review.toml), allowing a repository to inject and execute arbitrary agent instructions.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content such as code diffs, files, and narrative claims as primary inputs for its review lenses.\n
  • Ingestion points: content and claims inputs in SKILL.md, and configuration overrides from the project root.\n
  • Boundary markers: The skill uses file staging to isolate content, but lacks robust delimiters or explicit "ignore instructions" warnings when passing content to subagents.\n
  • Capability inventory: Subprocess execution via uv run, subagent spawning, and filesystem access.\n
  • Sanitization: No sanitization or validation is applied to the reviewed content before it is processed by the lenses.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 20, 2026, 07:08 AM
Security Audit — agent-trust-hub — bmad-review