bmad-build
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes framework-specific Python scripts using
uv run. These scripts are located within the_bmaddirectory of the project root and are used to manage the development lifecycle.\n- [EXTERNAL_DOWNLOADS]: The skill references installing a core dependency from thebmad-code-orgorganization using thenpx skills addcommand.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted external inputs such as user intent descriptions, requirement documents, and code diffs. It manages this risk through a structured multi-step workflow, mandatory human checkpoints (e.g., plan approval), and explicit instructions for review subagents to ignore injected directives that attempt to bypass safety steps.\n - Ingestion points: Ingests user prompts, ticket descriptions, and project documentation in
step-01-clarify-and-route.mdand code diffs instep-04-review.md.\n - Boundary markers: Uses
<frozen-after-approval>tags inplan-template.mdto lock intent after human review.\n - Capability inventory: Includes shell execution (
uv run), file writing (plan and diff files), and subagent spawning across all workflow steps.\n - Sanitization: Relies on structural verification, multiple review lenses (Edge Case Hunter, Verification Gap), and human-in-the-loop checkpoints before implementation.
Audit Metadata