bmad-review
Warn
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill executes
uv runcommands inSKILL.mdto resolve customization settings using a project-specific script ({project-root}/_bmad/scripts/resolve_customization.py) and to calculate word metrics. While these are part of the intended workflow, executing scripts from the project root (which might be user-controlled or untrusted) poses a risk. - [DYNAMIC_CONTEXT_INJECTION]: The skill uses the
!syntax (e.g., in the forwarded activation steps or general execution flow) to run shell commands at load time to populate context. This is used for git operations and BMad setup checks. - [INDIRECT_PROMPT_INJECTION]: The skill exhibits a significant attack surface for indirect injection. It ingests untrusted data (diffs, branches, files, claims) and passes them to multiple specialized subagents (lenses).
- Ingestion points:
SKILL.md(Step 2 and 5) processes content from branches, diffs, and local files. - Boundary markers: The skill mentions using unified diffs and unique temporary files, but there is no explicit instruction to the subagents to sanitize or ignore embedded malicious instructions within the reviewed content.
- Capability inventory: The skill can execute shell commands via
uv runand has broad file system access to read project configurations and the content to be reviewed. - Sanitization: No evidence of active sanitization or escaping of the ingested content before it is passed to the LLM-based lenses.
- [DYNAMIC_EXECUTION]: The
resolve_customization.pyscript dynamically determines theworkflowconfiguration, which can includeactivation_steps,on_completehooks, andinstructionsets for lenses. This allows for runtime modification of the agent's logic based on local project files. - [EXTERNAL_DOWNLOADS]: The skill refers to
npx skills add bmad-code-org/BMAD-METHODto install dependencies if not present. This is a reference to a well-known vendor resource but involves downloading external code.
Audit Metadata