bmad-deep-recon
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [SAFE]: The skill uses local, deterministic Python scripts (
recon_kit.py,memlog.py) to manage research logs, tally claims, and validate citations. These scripts rely exclusively on Python standard libraries and do not perform unauthorized network or file system operations. - [SAFE]: Implements a strict 'research firewall' policy (defined in
SKILL.md), ensuring that subagents spawned for web research are restricted to their specific briefs and lack access to project-sensitive files, environment variables, or ambient context. - [INDIRECT_PROMPT_INJECTION]: As a research tool, the skill naturally ingests untrusted data from web searches and external reports. It mitigates this risk by using fresh-context subagents for extraction and creating 'relevance-filtered digests' instead of directly ingesting raw external content into the primary agent's context.
- [COMMAND_EXECUTION]: The skill instructs the agent to execute local scripts via
uv run. These operations are limited to the skill's own orchestration tools for logging and configuration management, with no evidence of unsafe interpolation of user input into these shell commands. - [SAFE]: The HTML briefing generator (
references/html-briefing.md) requires reports to be self-contained and offline-first, explicitly prohibiting external requests for fonts, images, or scripts (CDNs), which effectively prevents data exfiltration or tracking via generated research artifacts.
Audit Metadata