bmad-toolsmith

Pass

Audited by Gen Agent Trust Hub on Oct 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a significant attack surface for indirect prompt injection as its primary function involves processing untrusted or external data to generate code and agent instructions.
  • Ingestion points: The skill ingests data from local session logs (read_session_log.py), external prompt files, Cursor rules, and system prompts from other tools (modes/convert.md).
  • Boundary markers: There are no explicit boundary markers or sanitization steps documented when the AI is instructed to 'Read the source whole' and 'Extract' know-how from these untrusted inputs.
  • Capability inventory: The Toolsmith can write new files to the filesystem (init_skill.py), execute scripts (uv run), and recommend the installation of additional skills.
  • Sanitization: The skill lacks explicit sanitization or filtering of the content extracted from logs or external prompts before it is interpolated into new skill templates.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the download and installation of additional tools and skills.
  • Evidence: Instructions in SKILL.md and discover.md suggest using npx skills add bmad-code-org/BMAD-METHOD --skill <name> to install dependencies or related modules.
  • Trust Scope: These downloads target the official GitHub repository of the skill's author (bmad-code-org), which is a vendor-owned resource.
  • [COMMAND_EXECUTION]: The skill relies on local command execution to perform its utility functions.
  • Evidence: The skill frequently invokes Python scripts using the uv run command (e.g., uv run {skill-root}/scripts/count_tokens.py).
  • Evidence: The test suite (e.g., scripts/tests/test_init_skill.py) uses subprocess.run to execute the skill's utility scripts for validation purposes.
  • [DYNAMIC_EXECUTION]: The skill generates and executes content at runtime through templating and automated scaffolding.
  • Evidence: process_template.py dynamically replaces variables and conditional blocks in Markdown and Python templates to create new skills.
  • Evidence: init_skill.py and init-sanctum.py automatically create file structures and write initial scripts and configurations based on user-defined shapes (e.g., memory-agent, script-utility).
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 6, 2026, 02:36 PM