bmad-review

Warn

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes uv run commands in SKILL.md to resolve customization settings using a project-specific script ({project-root}/_bmad/scripts/resolve_customization.py) and to calculate word metrics. While these are part of the intended workflow, executing scripts from the project root (which might be user-controlled or untrusted) poses a risk.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses the ! syntax (e.g., in the forwarded activation steps or general execution flow) to run shell commands at load time to populate context. This is used for git operations and BMad setup checks.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits a significant attack surface for indirect injection. It ingests untrusted data (diffs, branches, files, claims) and passes them to multiple specialized subagents (lenses).
  • Ingestion points: SKILL.md (Step 2 and 5) processes content from branches, diffs, and local files.
  • Boundary markers: The skill mentions using unified diffs and unique temporary files, but there is no explicit instruction to the subagents to sanitize or ignore embedded malicious instructions within the reviewed content.
  • Capability inventory: The skill can execute shell commands via uv run and has broad file system access to read project configurations and the content to be reviewed.
  • Sanitization: No evidence of active sanitization or escaping of the ingested content before it is passed to the LLM-based lenses.
  • [DYNAMIC_EXECUTION]: The resolve_customization.py script dynamically determines the workflow configuration, which can include activation_steps, on_complete hooks, and instruction sets for lenses. This allows for runtime modification of the agent's logic based on local project files.
  • [EXTERNAL_DOWNLOADS]: The skill refers to npx skills add bmad-code-org/BMAD-METHOD to install dependencies if not present. This is a reference to a well-known vendor resource but involves downloading external code.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 2, 2026, 10:29 PM
Security Audit — agent-trust-hub — bmad-review