bmad-brainstorming

Warn

Audited by Socket on Aug 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated purpose is benign and mostly aligned with local memlog/config handling, but it executes project-local scripts at activation, creating a trust boundary break with the working tree. No clear credential theft, exfiltration endpoint, or malware behavior is shown, yet the install/execution model is riskier than necessary for a brainstorming coach.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Aug 30, 2026, 10:43 PM
Package URL
pkg:socket/skills-sh/bmad-code-org%2Fbmad-skills%2Fbmad-brainstorming%2F@094676330ae51f152e06ac3ea16978994c733fdd68ca7538d7db47d9b568bbcd
Security Audit — socket — bmad-brainstorming