gds-performance-test
Pass
Audited by Gen Agent Trust Hub on Jul 7, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: Executes a local Python utility script (
resolve_customization.py) from the project's internal directory structure (_bmad/scripts/) to manage workflow configurations and completion steps. - [DATA_EXPOSURE]: Accesses project-level files such as
config.yaml,customize.toml, and files matching theproject-context.mdpattern to extract metadata for the generated test plan. - [INDIRECT_PROMPT_INJECTION]: The workflow is driven by external configuration files in YAML and TOML formats. This creates an attack surface where the agent's behavior could be influenced by the contents of these project files.
Audit Metadata