gds-agent-tech-writer

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local Python script at {project-root}/_bmad/scripts/resolve_customization.py during activation to merge configuration files (SKILL.md).
  • [INDIRECT_PROMPT_INJECTION]: The update-standards.md component allows users to append 'CRITICAL' rules to the documentation-standards.md file. These rules are subsequently used as high-priority instructions for the agent, creating a risk where malicious input could persistently alter the agent's behavior or safety constraints.
  • [INDIRECT_PROMPT_INJECTION]: The agent is designed to ingest and analyze untrusted external data, such as project-context.md files and user-submitted documents for validation. These inputs could contain hidden instructions intended to influence the agent's output or the execution of its writing tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 08:00 PM
Security Audit — agent-trust-hub — gds-agent-tech-writer