bmad-spec
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute specific Python utility scripts using
uv run. These scripts, includingresolve_customization.py,resolve_config.py, andmemlog.py, are located in the{project-root}/_bmad/scripts/directory. These appear to be vendor-provided framework resources for the BMad ecosystem. - [DATA_EXFILTRATION]: The skill implements a
persistent_factsmechanism withincustomize.tomlthat allows loading the contents of local files into the agent's context using glob patterns (prefixed withfile:). This capability could potentially be used to expose sensitive information if overly broad globs are configured. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data, such as Slack transcripts, customer emails, and RFCs, which may contain malicious instructions meant to influence agent behavior.
- Ingestion points: The 'Operation' section in
SKILL.mddetails the ingestion of multi-source inputs, including unstructured brain dumps and external transcripts. - Boundary markers: The instructions do not specify the use of clear delimiters or 'ignore' instructions for the untrusted content being processed.
- Capability inventory: The skill possesses file-writing capabilities (creating
SPEC.md, companions, andstories.yaml) and command execution capabilities throughuv run. - Sanitization: The skill employs a 'Spec Law' validation framework and a two-pass 'Self-Validate' sweep to verify the integrity and coherence of the output distilled from external inputs.
- [DYNAMIC_EXECUTION]: The skill's activation logic requires the agent to execute arbitrary sequences of instructions defined in configuration fields, specifically
activation_steps_prepend,activation_steps_append, andon_complete.
Audit Metadata