bmad-agent-dev

Warn

Audited by Socket on Sep 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Suspicious due to explicit transitive skill installation, but not malicious. The main behavior is coherent for a BMAD developer-agent skill: it loads local project config, adopts a persona, and dispatches workflows. Risk comes from broad local-config-driven execution and especially from instructing the agent to fetch/install other skills, which extends trust to external skill content.

Confidence: 91%Severity: 52%
Audit Metadata
Analyzed At
Sep 28, 2026, 08:30 PM
Package URL
pkg:socket/skills-sh/bmad-code-org%2Fbmad-method%2Fbmad-agent-dev%2F@3a4867cdd121b4cfb49fad6b9f0ad5e8d109ce7e8f704306cf5aceae6f3318d0
Security Audit — socket — bmad-agent-dev