bmad-review
Warn
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a Python script from the project root directory:
uv run {project-root}/_bmad/scripts/resolve_customization.py. This presents a security risk if the repository being reviewed contains a malicious script at that path designed to exploit the agent during the review process.\n- [DYNAMIC_EXECUTION]: The skill executes "literal instructions" defined in configuration fieldsactivation_steps_prepend,activation_steps_append, andon_complete. These fields are loaded fromcustomize.tomland can be overridden by project-specific configuration files (e.g.,{project-root}/_bmad/custom/bmad-review.toml), allowing a repository to inject and execute arbitrary agent instructions.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content such as code diffs, files, and narrative claims as primary inputs for its review lenses.\n - Ingestion points:
contentandclaimsinputs inSKILL.md, and configuration overrides from the project root.\n - Boundary markers: The skill uses file staging to isolate content, but lacks robust delimiters or explicit "ignore instructions" warnings when passing content to subagents.\n
- Capability inventory: Subprocess execution via
uv run, subagent spawning, and filesystem access.\n - Sanitization: No sanitization or validation is applied to the reviewed content before it is processed by the lenses.
Audit Metadata