bmad-agent-pm
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local Python scripts during its activation process to resolve configuration and customization settings.\n
- Evidence:
uv run {project-root}/_bmad/scripts/resolve_customization.pyinSKILL.md(Step 1).\n - Evidence:
uv run {project-root}/_bmad/scripts/resolve_config.pyinSKILL.md(Step 5).\n- [DYNAMIC_EXECUTION]: The skill dynamically executes sequences of instructions defined in configuration files through 'prepend' and 'append' activation steps.\n - Evidence:
Execute each entry in {agent.activation_steps_prepend}and{agent.activation_steps_append}inSKILL.md.\n- [INDIRECT_PROMPT_INJECTION]: The skill aggregates persona details, principles, and persistent facts from multiple project-level configuration files (.toml), which could be influenced by untrusted project content.\n - Ingestion points:
customize.toml,{project-root}/_bmad/custom/{skill-name}.toml, and{project-root}/_bmad/custom/{skill-name}.user.toml.\n - Boundary markers: None provided to distinguish system instructions from external configuration.\n
- Capability inventory: Execution of shell commands via
uv runandnpx, and broad file reading capabilities.\n - Sanitization: No sanitization or validation of the merged configuration content is performed before adopting the persona or executing steps.\n- [EXTERNAL_DOWNLOADS]: The skill references and recommends the installation of additional tools from the vendor's GitHub repository.\n
- Evidence:
npx skills add bmad-code-org/BMAD-METHOD --skill bmadinSKILL.md.\n - Evidence:
source = "github:bmad-code-org/BMAD-METHOD/skills"inbmod.toml.
Audit Metadata