bm-decide

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE]: The skill reads local configuration files from the user's home directory (~/.claude/settings.json) and project-specific settings (.claude/settings.json, .claude/settings.local.json). This data is used to resolve primaryProject IDs and determine file placement conventions for recording decisions.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied information from the conversation history, including decision rationales and consequences, to generate persistent notes. This represents a potential surface where untrusted data could influence the agent's output during the note-drafting phase.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 02:04 AM
Security Audit — agent-trust-hub — bm-decide