bmad-advanced-elicitation
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
uv runcommand to execute local Python scripts includingresolve_customization.py,pick_methods.py, androster.py. These scripts are part of the skill's distribution or the underlying framework and are used to manage method catalogs and agent personas. - [EXTERNAL_DOWNLOADS]: The instructions suggest using
npx skills add bmad-code-org/BMAD-METHODto install dependency skills if they are missing. This points to the official repository of the skill's author. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process previous conversation history to provide refinements, which is an inherent attack surface for indirect prompt injection.
- Ingestion points: Processes conversation history (the target) and reads method definitions from
methods.csvand customization files in{project-root}/_bmad/custom/. - Boundary markers: The skill explicitly halts and requires the user to select 'Apply' or 'Reject' for any proposed changes, acting as a human-in-the-loop safety checkpoint.
- Capability inventory: The skill can execute local scripts via
uv runas part of its core logic. - Sanitization: Uses standard
csv.DictReaderandjson.loadsinscripts/pick_methods.pyto parse method data, ensuring data is handled as structured input rather than executable instructions.
Audit Metadata