bmad-agent-architect
Fail
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: HIGHCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill executes Python scripts located in the project's local directory (
{project-root}/_bmad/scripts/resolve_customization.pyandresolve_config.py) usinguv run. This allows for the execution of arbitrary local code, which is a high-risk pattern if the project being analyzed was cloned from an untrusted source. - [DYNAMIC_EXECUTION]: The skill implements a dynamic execution flow where it processes and runs command strings stored in
activation_steps_prependandactivation_steps_append. These steps are loaded from project-specific configuration files, effectively allowing the project environment to control the agent's actions. - [INDIRECT_PROMPT_INJECTION]: The skill is highly susceptible to configuration-based injection by merging data from untrusted files in the project's
_bmad/custom/directory. - Ingestion points:
SKILL.mdmerges instructions and settings from{project-root}/_bmad/custom/{skill-name}.tomland its.user.tomlvariant. - Boundary markers: Absent; the merged configuration is treated as foundational context for the agent's persona and logic.
- Capability inventory: Includes subprocess execution via
uv run, shell command execution through activation steps, and file read access viapersistent_factsglobs. - Sanitization: No validation or sanitization is performed on the commands or facts loaded from the project-local configuration.
- [EXTERNAL_DOWNLOADS]: The skill includes instructions to download and install additional skills from the
bmad-code-orgGitHub organization usingnpx skills add. While these are vendor-owned resources, they represent the dynamic retrieval of external code.
Recommendations
- AI detected serious security threats
Audit Metadata