bmad-prfaq
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local Python scripts (
resolve_customization.py,resolve_config.py) usinguv runduring its activation and completion phases. It also contains logic to execute arbitrary instructions provided via theon_complete,activation_steps_prepend, andactivation_steps_appendconfiguration fields. - [EXTERNAL_DOWNLOADS]: The skill suggests the installation of the core
bmadskill from thebmad-code-orgGitHub organization using thenpx skills addcommand if the environment is not already configured. - [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and synthesizes data from untrusted sources, including local documents and web search results.
- Ingestion points: The
Artifact Analyzeragent scans local project directories for documents, and theWeb Researcheragent retrieves content from the internet. - Boundary markers: No explicit delimiters or instructions to ignore embedded commands are used when processing the ingested data.
- Capability inventory: The skill has access to the local file system, web search tools, and subprocess execution capabilities via
uv run. - Sanitization: There is no evidence of sanitization or filtering of the external content before it is processed by the agent.
Audit Metadata