bmad-retrospective
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes a Python script (
git_evidence.py) to executegit logand other git commands. The script includes logic to validate the revision range and strip environment variables, effectively preventing command injection and unauthorized environment manipulation. - [COMMAND_EXECUTION]: The skill executes local utility scripts, including
tickets.pyandrender_skill.py, which are part of the project's internal BMad infrastructure, to query project status and manage skill rendering. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted project artifacts which could contain malicious instructions. Mandatory Evidence Chain: (1) Ingestion points: Epic files, initiative requirements, ticket plans, and session logs; (2) Boundary markers: The workflow explicitly marks findings as unverified until re-checked against primary sources; (3) Capability inventory: Executes
gitandtickets.pyvia subprocesses; (4) Sanitization: Thegit_evidence.pyscript validates inputs for revision ranges. - [EXTERNAL_DOWNLOADS]: The skill recommends installing base components from the official vendor repository (
bmad-code-org/BMAD-METHOD) using platform-standard commands, following trusted vendor guidelines.
Audit Metadata