bmad-project-context

Warn

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill executes Python scripts located at {project-root}/_bmad/scripts/resolve_customization.py and {project-root}/_bmad/scripts/resolve_config.py using the uv run command during its activation sequence. It also allows for the execution of arbitrary commands defined in the activation_steps_prepend and activation_steps_append fields of the customization configuration file found in the workspace.- [INDIRECT_PROMPT_INJECTION]: The skill has a broad ingestion surface, reading files like AGENTS.md, package.json, and documentation to synthesize instructions. Evidence Chain: (1) Ingestion points: AGENTS.md, manifests, and docs; (2) Boundary markers: Absent for ingestion; (3) Capability inventory: uv run (subprocess) and file-writing; (4) Sanitization: None identified for interpolated content.- [COMMAND_EXECUTION]: The skill utilizes shell commands to interact with the local environment, including uv run for script execution and git log for verifying historical changes in the repository.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 2, 2026, 10:30 PM
Security Audit — agent-trust-hub — bmad-project-context