bmad-create-epics-and-stories

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local Python scripts (resolve_customization.py, resolve_config.py) using the uv run command. These scripts are located within the project's _bmad/scripts/ directory and are used to manage workflow customization and configuration. This behavior is consistent with the framework provided by the skill author.
  • [INDIRECT_PROMPT_INJECTION]: The workflow relies on reading and extracting information from external project documents including PRD.md, Architecture.md, and UX design files. These files represent untrusted ingestion points where malicious instructions could be embedded to manipulate the agent's logic during the story creation process.
  • Ingestion points: Functional and non-functional requirements are extracted from PRD.md, technical constraints from Architecture.md, and design requirements from DESIGN.md and EXPERIENCE.md files.
  • Boundary markers: No explicit delimiters or instructions are used to distinguish ingested data from the skill's own instructions.
  • Capability inventory: The skill has the ability to write generated markdown files to the project's artifact directory and execute local framework scripts.
  • Sanitization: There is no evidence of validation or sanitization of the text extracted from the source documents before it is processed by the agent.
  • [DYNAMIC_EXECUTION]: The skill supports an on_complete hook defined in the customize.toml configuration. When the workflow finishes, the agent resolves this value and executes it as a shell command. This allows for dynamic command execution based on the contents of local configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 08:28 PM
Security Audit — agent-trust-hub — bmad-create-epics-and-stories