bmad-architecture

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill frequently executes local Python scripts using uv run to handle task-specific logic. These include memlog.py for state management, resolve_customization.py for configuration, and lint_spine.py for deterministic document validation.
  • [EXTERNAL_DOWNLOADS]: The skill references the bmad-code-org GitHub organization for method definitions and skill updates. Additionally, the test suite for the linter script declares a dependency on the well-known pytest package.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process potentially untrusted external data, such as project specifications, raw ideas, and existing source code, to generate architectural artifacts.
  • Ingestion points: Reads from SPEC.md, user-provided ideas, and specified codebase paths in the project directory.
  • Boundary markers: Employs a multi-stage review process using specialized subagents and a mechanical linter script to ensure output integrity.
  • Capability inventory: Capable of executing shell commands through the uv tool and writing files to the project's documentation workspace.
  • Sanitization: Instructs the agent to verify all referenced technology versions against official web sources and project constraints rather than relying solely on training data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 08:59 PM
Security Audit — agent-trust-hub — bmad-architecture