bmad-build-auto

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a project-local Python script located at _bmad/scripts/render_skill.py using the uv run command. This execution is central to the skill's primary purpose of driving the development loop.
  • [EXTERNAL_DOWNLOADS]: The instructions include a command to install a related developer tool using npx skills add from the bmad-code-org GitHub repository. This is used for initial environment setup and targets the official repository of the skill's author.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes project-derived data, including unified diffs, ticket information, and planning documents, which could contain instructions intended to influence agent behavior.
  • Ingestion points: The step-04-review.md workflow and specific review lens instructions (e.g., review-prompts/edge-case-hunter.md) read diff files and plan documents from the local filesystem to perform their analysis.
  • Boundary markers: The plan-template.md utilizes a defined <intent-contract> block to encapsulate the high-level intent, separating it from agent-generated implementation details and providing a read-only section for the implementer.
  • Capability inventory: The skill is capable of executing local shell commands via uv and spawning multiple subagents to perform distinct review and implementation tasks.
  • Sanitization: The review process minimizes direct prompt interpolation of untrusted content by having subagents read the diff and plan files directly from the filesystem rather than including the content in the launch prompt.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 11:20 PM
Security Audit — agent-trust-hub — bmad-build-auto