bmad-build-auto
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a project-local Python script located at
_bmad/scripts/render_skill.pyusing theuv runcommand. This execution is central to the skill's primary purpose of driving the development loop. - [EXTERNAL_DOWNLOADS]: The instructions include a command to install a related developer tool using
npx skills addfrom thebmad-code-orgGitHub repository. This is used for initial environment setup and targets the official repository of the skill's author. - [INDIRECT_PROMPT_INJECTION]: The skill processes project-derived data, including unified diffs, ticket information, and planning documents, which could contain instructions intended to influence agent behavior.
- Ingestion points: The
step-04-review.mdworkflow and specific review lens instructions (e.g.,review-prompts/edge-case-hunter.md) read diff files and plan documents from the local filesystem to perform their analysis. - Boundary markers: The
plan-template.mdutilizes a defined<intent-contract>block to encapsulate the high-level intent, separating it from agent-generated implementation details and providing a read-only section for the implementer. - Capability inventory: The skill is capable of executing local shell commands via
uvand spawning multiple subagents to perform distinct review and implementation tasks. - Sanitization: The review process minimizes direct prompt interpolation of untrusted content by having subagents read the diff and plan files directly from the filesystem rather than including the content in the launch prompt.
Audit Metadata