bmad-eval
Audited by Socket on Oct 6, 2026
2 alerts found:
Anomalyx2The code has a clear conditional disclosure path for token-like values read from skill files, and it records selected environment data in the working directory. It also modifies skill files under a prompt-controlled condition. These behaviors could be intentional in a test fixture, but the token disclosure and file modification should be considered before running it with real secrets or valuable files.
The fragment is not executable malware, but it recommends running prompts with permission and possibly sandbox protections disabled and copying authentication material into a fresh HOME. Those practices create meaningful security exposure if the runner or prompt is not trusted. No explicit exfiltration or system-damaging behavior is present in the supplied text.