bmad-walkthrough
Fail
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
uv runto execute a Python script located at{project-root}/_bmad/scripts/resolve_customization.py. Since{project-root}refers to the repository being reviewed, a malicious project could include a script at this path to gain code execution on the agent's environment. - [REMOTE_CODE_EXECUTION]: Executing logic sourced from the untrusted project under review (via the customization resolver script) effectively allows for remote code execution by whoever controls the project repository.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data. 1. Ingestion points: Git diffs and full file contents (SKILL.md, orientation.md, generate-trail.md). 2. Boundary markers: Absent. 3. Capability inventory:
uv run(shell),gh(network/tool),git(tool). 4. Sanitization: Absent. This vulnerability could be used by an attacker to manipulate the agent into performing unauthorized actions. - [DATA_EXFILTRATION]: The
persistent_factsmechanism allows loading the contents of any file matched by a glob pattern under{project-root}. An attacker could configure the skill viacustomize.tomlto load sensitive files into the agent's context, which acts as a data exposure vector.
Recommendations
- AI detected serious security threats
Audit Metadata