bmad-advanced-elicitation

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the uv run command to execute local Python scripts including resolve_customization.py, pick_methods.py, and roster.py. These scripts are part of the skill's distribution or the underlying framework and are used to manage method catalogs and agent personas.
  • [EXTERNAL_DOWNLOADS]: The instructions suggest using npx skills add bmad-code-org/BMAD-METHOD to install dependency skills if they are missing. This points to the official repository of the skill's author.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process previous conversation history to provide refinements, which is an inherent attack surface for indirect prompt injection.
  • Ingestion points: Processes conversation history (the target) and reads method definitions from methods.csv and customization files in {project-root}/_bmad/custom/.
  • Boundary markers: The skill explicitly halts and requires the user to select 'Apply' or 'Reject' for any proposed changes, acting as a human-in-the-loop safety checkpoint.
  • Capability inventory: The skill can execute local scripts via uv run as part of its core logic.
  • Sanitization: Uses standard csv.DictReader and json.loads in scripts/pick_methods.py to parse method data, ensuring data is handled as structured input rather than executable instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 10:30 PM
Security Audit — agent-trust-hub — bmad-advanced-elicitation