bmad-spec
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process potentially untrusted external content as its primary function.
- Ingestion points: The skill reads from various sources including meeting transcripts, Slack threads, customer emails, and mixed multi-source brain dumps as described in SKILL.md.
- Boundary markers: There are no explicit prompt-level delimiters or instructions specified to isolate the untrusted input from the agent's core operating instructions, which may allow embedded instructions in the data to influence agent behavior.
- Capability inventory: The skill has the capability to execute local shell commands via uv run and perform file system writes to the project workspace.
- Sanitization: The instructions do not include specific sanitization, filtering, or escaping steps for the content processed from these external inputs.
- [COMMAND_EXECUTION]: The skill instructions direct the agent to execute several shell commands using uv run to interface with Python scripts (e.g., resolve_customization.py, resolve_config.py, memlog.py) located in the project's _bmad/scripts/ directory.
- [DYNAMIC_EXECUTION]: The workflow allows for the execution of arbitrary steps defined in the customize.toml file (activation_steps_prepend, activation_steps_append), enabling project-specific command execution outside the main instruction file.
- [EXTERNAL_DOWNLOADS]: The skill suggests installing the bmad management tool via npx skills add bmad-code-org/BMAD-METHOD. This reference targets the official repository of the skill's author.
Audit Metadata