bmad-retrospective

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a Python script (git_evidence.py) to execute git log and other git commands. The script includes logic to validate the revision range and strip environment variables, effectively preventing command injection and unauthorized environment manipulation.
  • [COMMAND_EXECUTION]: The skill executes local utility scripts, including tickets.py and render_skill.py, which are part of the project's internal BMad infrastructure, to query project status and manage skill rendering.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted project artifacts which could contain malicious instructions. Mandatory Evidence Chain: (1) Ingestion points: Epic files, initiative requirements, ticket plans, and session logs; (2) Boundary markers: The workflow explicitly marks findings as unverified until re-checked against primary sources; (3) Capability inventory: Executes git and tickets.py via subprocesses; (4) Sanitization: The git_evidence.py script validates inputs for revision ranges.
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing base components from the official vendor repository (bmad-code-org/BMAD-METHOD) using platform-standard commands, following trusted vendor guidelines.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 10:35 PM
Security Audit — agent-trust-hub — bmad-retrospective