bmad-ticket
Warn
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONOBFUSCATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The scripts/tickets.py script dynamically loads a configuration module (config_utils.py) from a runtime-computed project path using importlib.util.spec_from_file_location. This allows the execution of code from paths defined within the project structure.
- [OBFUSCATION]: The scripts/tests/test_tickets.py file contains a hidden Line Separator Unicode character (U+2028) within a test string. While identified in a test context for verifying character handling, hidden characters can be used to obfuscate malicious content.
- [COMMAND_EXECUTION]: The SKILL.md file defines workflows that involve the execution of shell commands through the uv run utility to run project-local scripts for configuration and ticket management.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources like tickets.toml and markdown files. The absence of explicit boundary markers when interpolating this data into logic or potential CLI commands creates an attack surface where maliciously crafted ticket content could influence agent behavior.
Audit Metadata