bmad-correct-course

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local Python scripts (resolve_customization.py, resolve_config.py) using uv run. These scripts are located within the project's _bmad/scripts/ directory and are used to manage workflow customization and project configuration.\n- [EXTERNAL_DOWNLOADS]: The skill initiates the installation of the bmad skill from the bmad-code-org/BMAD-METHOD repository on GitHub via npx skills add. This is a vendor-owned resource required for the skill's setup process.\n- [INDIRECT_PROMPT_INJECTION]: The skill assesses change impacts by ingesting various project documents, such as PRDs, architecture guides, and UX designs.\n
  • Ingestion points: Document Discovery process in SKILL.md loading files from the {planning_artifacts}/ directory.\n
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore potential malicious content within these documents.\n
  • Capability inventory: The skill can execute shell commands via uv run and write new proposal documents to the file system.\n
  • Sanitization: No sanitization or validation of the ingested document content is performed before processing.\n- [DYNAMIC_EXECUTION]: Upon completion (Step 6), the skill resolves a value from the workflow.on_complete configuration key and instructs the agent to follow it as the final terminal instruction. This allows for dynamic extension of the skill's behavior based on local configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 10:10 PM
Security Audit — agent-trust-hub — bmad-correct-course