bmad-agent-pm

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local Python scripts during its activation process to resolve configuration and customization settings.\n
  • Evidence: uv run {project-root}/_bmad/scripts/resolve_customization.py in SKILL.md (Step 1).\n
  • Evidence: uv run {project-root}/_bmad/scripts/resolve_config.py in SKILL.md (Step 5).\n- [DYNAMIC_EXECUTION]: The skill dynamically executes sequences of instructions defined in configuration files through 'prepend' and 'append' activation steps.\n
  • Evidence: Execute each entry in {agent.activation_steps_prepend} and {agent.activation_steps_append} in SKILL.md.\n- [INDIRECT_PROMPT_INJECTION]: The skill aggregates persona details, principles, and persistent facts from multiple project-level configuration files (.toml), which could be influenced by untrusted project content.\n
  • Ingestion points: customize.toml, {project-root}/_bmad/custom/{skill-name}.toml, and {project-root}/_bmad/custom/{skill-name}.user.toml.\n
  • Boundary markers: None provided to distinguish system instructions from external configuration.\n
  • Capability inventory: Execution of shell commands via uv run and npx, and broad file reading capabilities.\n
  • Sanitization: No sanitization or validation of the merged configuration content is performed before adopting the persona or executing steps.\n- [EXTERNAL_DOWNLOADS]: The skill references and recommends the installation of additional tools from the vendor's GitHub repository.\n
  • Evidence: npx skills add bmad-code-org/BMAD-METHOD --skill bmad in SKILL.md.\n
  • Evidence: source = "github:bmad-code-org/BMAD-METHOD/skills" in bmod.toml.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 08:29 PM
Security Audit — agent-trust-hub — bmad-agent-pm