bmad-spec

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process potentially untrusted external content as its primary function.
  • Ingestion points: The skill reads from various sources including meeting transcripts, Slack threads, customer emails, and mixed multi-source brain dumps as described in SKILL.md.
  • Boundary markers: There are no explicit prompt-level delimiters or instructions specified to isolate the untrusted input from the agent's core operating instructions, which may allow embedded instructions in the data to influence agent behavior.
  • Capability inventory: The skill has the capability to execute local shell commands via uv run and perform file system writes to the project workspace.
  • Sanitization: The instructions do not include specific sanitization, filtering, or escaping steps for the content processed from these external inputs.
  • [COMMAND_EXECUTION]: The skill instructions direct the agent to execute several shell commands using uv run to interface with Python scripts (e.g., resolve_customization.py, resolve_config.py, memlog.py) located in the project's _bmad/scripts/ directory.
  • [DYNAMIC_EXECUTION]: The workflow allows for the execution of arbitrary steps defined in the customize.toml file (activation_steps_prepend, activation_steps_append), enabling project-specific command execution outside the main instruction file.
  • [EXTERNAL_DOWNLOADS]: The skill suggests installing the bmad management tool via npx skills add bmad-code-org/BMAD-METHOD. This reference targets the official repository of the skill's author.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 10:30 PM
Security Audit — agent-trust-hub — bmad-spec