bmad-party-mode
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/resolve_party.pyusessubprocess.runto execute auxiliary Python scripts (e.g.,roster.py,resolve_config.py,resolve_customization.py) located within the project's_bmad/scriptsdirectory. This is used to resolve agent rosters and configuration settings dynamically. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest untrusted external data, such as customer profiles, survey exports, and interview notes, to "distill" them into AI personas (
references/create-party.md). It also reads from append-only memory logs (.memlog.md) that accumulate content throughout sessions. Malicious instructions embedded in these data sources could influence the behavior of the personas or the orchestrator. - Ingestion points: Data provided for persona distillation in
references/create-party.mdand per-party memlogs inreferences/party-memory.md. - Boundary markers: The instructions suggest weaving personas into prompts, but no explicit sanitization or strict boundary markers for the ingested data are shown in the provided logic.
- Capability inventory: The skill can execute local scripts via
subprocessand write to the filesystem viamemlog.py. - Sanitization: None detected for the natural language content distilled from external data.
- [SAFE]: The skill uses
npxto install a related tool (bmad-code-org/BMAD-METHOD), which originates from the same vendor as the skill author and is consistent with the skill's primary purpose.
Audit Metadata