bmad-party-mode

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/resolve_party.py uses subprocess.run to execute auxiliary Python scripts (e.g., roster.py, resolve_config.py, resolve_customization.py) located within the project's _bmad/scripts directory. This is used to resolve agent rosters and configuration settings dynamically.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest untrusted external data, such as customer profiles, survey exports, and interview notes, to "distill" them into AI personas (references/create-party.md). It also reads from append-only memory logs (.memlog.md) that accumulate content throughout sessions. Malicious instructions embedded in these data sources could influence the behavior of the personas or the orchestrator.
  • Ingestion points: Data provided for persona distillation in references/create-party.md and per-party memlogs in references/party-memory.md.
  • Boundary markers: The instructions suggest weaving personas into prompts, but no explicit sanitization or strict boundary markers for the ingested data are shown in the provided logic.
  • Capability inventory: The skill can execute local scripts via subprocess and write to the filesystem via memlog.py.
  • Sanitization: None detected for the natural language content distilled from external data.
  • [SAFE]: The skill uses npx to install a related tool (bmad-code-org/BMAD-METHOD), which originates from the same vendor as the skill author and is consistent with the skill's primary purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 10:30 PM
Security Audit — agent-trust-hub — bmad-party-mode