bmad-agent-architect

Fail

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: HIGHCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes Python scripts located in the project's local directory ({project-root}/_bmad/scripts/resolve_customization.py and resolve_config.py) using uv run. This allows for the execution of arbitrary local code, which is a high-risk pattern if the project being analyzed was cloned from an untrusted source.
  • [DYNAMIC_EXECUTION]: The skill implements a dynamic execution flow where it processes and runs command strings stored in activation_steps_prepend and activation_steps_append. These steps are loaded from project-specific configuration files, effectively allowing the project environment to control the agent's actions.
  • [INDIRECT_PROMPT_INJECTION]: The skill is highly susceptible to configuration-based injection by merging data from untrusted files in the project's _bmad/custom/ directory.
  • Ingestion points: SKILL.md merges instructions and settings from {project-root}/_bmad/custom/{skill-name}.toml and its .user.toml variant.
  • Boundary markers: Absent; the merged configuration is treated as foundational context for the agent's persona and logic.
  • Capability inventory: Includes subprocess execution via uv run, shell command execution through activation steps, and file read access via persistent_facts globs.
  • Sanitization: No validation or sanitization is performed on the commands or facts loaded from the project-local configuration.
  • [EXTERNAL_DOWNLOADS]: The skill includes instructions to download and install additional skills from the bmad-code-org GitHub organization using npx skills add. While these are vendor-owned resources, they represent the dynamic retrieval of external code.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 29, 2026, 10:23 AM
Security Audit — agent-trust-hub — bmad-agent-architect