bmad-customize

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The discovery script scripts/list_customizable_skills.py scans sibling directories for customize.toml and SKILL.md files to extract customization options and descriptions. While reading data from other skills constitutes a surface for indirect prompt injection, the script uses structured TOML parsing and restricted regex patterns to extract only specific metadata fields.
  • Ingestion points: scripts/list_customizable_skills.py reads content from other skill directories within the environment.
  • Boundary markers: The script uses tomllib for structural parsing and enforces specific key lookups (e.g., agent, workflow, description).
  • Capability inventory: The skill instructions guide the agent to write TOML files to the {project-root}/_bmad/custom/ directory.
  • Sanitization: Employs tomllib.load() for safe parsing of configuration files.
  • [COMMAND_EXECUTION]: The test suite scripts/tests/test_list_customizable_skills.py uses subprocess.run to verify the CLI functionality of the discovery script. This execution is confined to the skill's own local scripts for testing purposes and does not incorporate untrusted input into the shell environment.
  • [DYNAMIC_EXECUTION]: The test script scripts/tests/test_list_customizable_skills.py utilizes importlib.util and exec_module to load the local discovery script as a module for unit testing. This is a standard development practice for testing Python scripts without environment installation.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 10:30 PM
Security Audit — agent-trust-hub — bmad-customize