bmad-build

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes framework-specific Python scripts using uv run. These scripts are located within the _bmad directory of the project root and are used to manage the development lifecycle.\n- [EXTERNAL_DOWNLOADS]: The skill references installing a core dependency from the bmad-code-org organization using the npx skills add command.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted external inputs such as user intent descriptions, requirement documents, and code diffs. It manages this risk through a structured multi-step workflow, mandatory human checkpoints (e.g., plan approval), and explicit instructions for review subagents to ignore injected directives that attempt to bypass safety steps.\n
  • Ingestion points: Ingests user prompts, ticket descriptions, and project documentation in step-01-clarify-and-route.md and code diffs in step-04-review.md.\n
  • Boundary markers: Uses <frozen-after-approval> tags in plan-template.md to lock intent after human review.\n
  • Capability inventory: Includes shell execution (uv run), file writing (plan and diff files), and subagent spawning across all workflow steps.\n
  • Sanitization: Relies on structural verification, multiple review lenses (Edge Case Hunter, Verification Gap), and human-in-the-loop checkpoints before implementation.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 10:00 PM
Security Audit — agent-trust-hub — bmad-build