bmad-loop-setup

Pass

Audited by Gen Agent Trust Hub on Aug 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches and installs the bmad-loop package from the author's Git repository at https://github.com/bmad-code-org/bmad-loop.git using uv tool install as part of the intended module setup.
  • [COMMAND_EXECUTION]: Executes the bmad-loop init command to register coding-CLI hooks and deploy bundled skills to the project directory.
  • [COMMAND_EXECUTION]: Runs bmad-loop validate to perform environment preflight checks and verify system readiness.
  • [COMMAND_EXECUTION]: Invokes a local Python script located at _bmad/scripts/resolve_config.py to retrieve project configuration settings such as user names and language preferences.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 29, 2026, 09:17 PM
Security Audit — agent-trust-hub — bmad-loop-setup