bmad-agent-dev

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes Python scripts located within the project's internal directory using the uv tool (e.g., {project-root}/_bmad/scripts/resolve_customization.py). This is a core functional pattern for the BMad framework to resolve environment-specific settings.
  • [INDIRECT_PROMPT_INJECTION]: The skill's operational parameters, including activation_steps and persistent_facts, are loaded from configuration files (customize.toml and overrides) found in the project root. These files can instruct the agent to perform specific sequences of actions or treat external content as foundational truths.
  • Ingestion points: Data is ingested from {skill-root}/customize.toml, {project-root}/_bmad/custom/{skill-name}.toml, and {project-root}/_bmad/custom/{skill-name}.user.toml.
  • Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are used when processing these configuration values.
  • Capability inventory: The agent has the capability to execute shell commands via uv run, read files into context, and invoke other installed skills.
  • Sanitization: No sanitization or validation of the activation steps or persistent facts is performed before execution or ingestion.
  • [EXTERNAL_DOWNLOADS]: The skill instructions suggest downloading additional components from the vendor's official GitHub repository (github:bmad-code-org/BMAD-METHOD/skills) using the npx skills add command if required modules are missing. These references target the author's own infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 08:28 PM
Security Audit — agent-trust-hub — bmad-agent-dev