bmad-spec

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute specific Python utility scripts using uv run. These scripts, including resolve_customization.py, resolve_config.py, and memlog.py, are located in the {project-root}/_bmad/scripts/ directory. These appear to be vendor-provided framework resources for the BMad ecosystem.
  • [DATA_EXFILTRATION]: The skill implements a persistent_facts mechanism within customize.toml that allows loading the contents of local files into the agent's context using glob patterns (prefixed with file:). This capability could potentially be used to expose sensitive information if overly broad globs are configured.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data, such as Slack transcripts, customer emails, and RFCs, which may contain malicious instructions meant to influence agent behavior.
  • Ingestion points: The 'Operation' section in SKILL.md details the ingestion of multi-source inputs, including unstructured brain dumps and external transcripts.
  • Boundary markers: The instructions do not specify the use of clear delimiters or 'ignore' instructions for the untrusted content being processed.
  • Capability inventory: The skill possesses file-writing capabilities (creating SPEC.md, companions, and stories.yaml) and command execution capabilities through uv run.
  • Sanitization: The skill employs a 'Spec Law' validation framework and a two-pass 'Self-Validate' sweep to verify the integrity and coherence of the output distilled from external inputs.
  • [DYNAMIC_EXECUTION]: The skill's activation logic requires the agent to execute arbitrary sequences of instructions defined in configuration fields, specifically activation_steps_prepend, activation_steps_append, and on_complete.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:08 AM
Security Audit — agent-trust-hub — bmad-spec