bmad-eval

Warn

Audited by Socket on Oct 6, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
scripts/tests/fake_harness.py

The code has a clear conditional disclosure path for token-like values read from skill files, and it records selected environment data in the working directory. It also modifies skill files under a prompt-controlled condition. These behaviors could be intentional in a test fixture, but the token disclosure and file modification should be considered before running it with real secrets or valuable files.

Confidence: 98%Severity: 62%
AnomalyLOW
references/harness.md

The fragment is not executable malware, but it recommends running prompts with permission and possibly sandbox protections disabled and copying authentication material into a fresh HOME. Those practices create meaningful security exposure if the runner or prompt is not trusted. No explicit exfiltration or system-damaging behavior is present in the supplied text.

Confidence: 96%Severity: 67%
Audit Metadata
Analyzed At
Oct 6, 2026, 02:39 PM
Package URL
pkg:socket/skills-sh/bmad-code-org%2Fbmad-method%2Fbmad-eval%2F@3f95baf36395e1909ba58e0e7325a585f2e23632b43eec7c30daf8a8aa30f14e