bmad-agent-dev
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill executes Python scripts located within the project's internal directory using the
uvtool (e.g.,{project-root}/_bmad/scripts/resolve_customization.py). This is a core functional pattern for the BMad framework to resolve environment-specific settings. - [INDIRECT_PROMPT_INJECTION]: The skill's operational parameters, including
activation_stepsandpersistent_facts, are loaded from configuration files (customize.tomland overrides) found in the project root. These files can instruct the agent to perform specific sequences of actions or treat external content as foundational truths. - Ingestion points: Data is ingested from
{skill-root}/customize.toml,{project-root}/_bmad/custom/{skill-name}.toml, and{project-root}/_bmad/custom/{skill-name}.user.toml. - Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are used when processing these configuration values.
- Capability inventory: The agent has the capability to execute shell commands via
uv run, read files into context, and invoke other installed skills. - Sanitization: No sanitization or validation of the activation steps or persistent facts is performed before execution or ingestion.
- [EXTERNAL_DOWNLOADS]: The skill instructions suggest downloading additional components from the vendor's official GitHub repository (
github:bmad-code-org/BMAD-METHOD/skills) using thenpx skills addcommand if required modules are missing. These references target the author's own infrastructure.
Audit Metadata