bmad-qa-generate-e2e-tests

Warn

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local Python scripts (resolve_customization.py and resolve_config.py) via uv run from the {project-root}/_bmad/scripts/ directory during the activation and completion phases. This execution relies on files located within the user's project workspace.
  • [COMMAND_EXECUTION]: In Step 4 of the execution workflow, the agent is instructed to run the project's native test commands (e.g., npm test or framework-specific CLIs) to verify that generated tests pass.
  • [INDIRECT_PROMPT_INJECTION]: The skill scans the project codebase, including package.json and implementation files, to auto-discover features and generate automated tests.
  • Ingestion points: Step 0 and Step 1 involve reading the codebase structure and contents from the project directory.
  • Boundary markers: The instructions do not define specific delimiters or "ignore instructions" markers for the ingested code content.
  • Capability inventory: The skill has the ability to execute subprocesses (uv run), write files (Step 5 summary), and execute shell commands (Step 4 tests).
  • Sanitization: There is no explicit requirement for the agent to sanitize or filter codebase content before using it to generate test logic.
  • [EXTERNAL_DOWNLOADS]: The skill references external resources for documentation and supplemental modules, specifically pointing to bmad-code-org.github.io and the bmad-code-org/BMAD-METHOD repository on GitHub for framework installation.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 28, 2026, 08:28 PM
Security Audit — agent-trust-hub — bmad-qa-generate-e2e-tests