bmad-correct-course

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses uv run to execute local Python scripts located at {project-root}/_bmad/scripts/resolve_customization.py and {project-root}/_bmad/scripts/resolve_config.py. These scripts are part of the bmad-code-org project infrastructure and are used for standard configuration resolution. There is no evidence of arbitrary command injection or unauthorized network activity in these calls.
  • [DATA_EXPOSURE]: The skill accesses project artifacts like PRD, Epics, and Architecture files. This access is consistent with its primary purpose of assessing change impact and generating proposals within the user's project environment. No external exfiltration of this data was observed.
  • [REMOTE_CODE_EXECUTION]: While the skill references a remote update source (github:bmad-code-org/bmad-skills/skills) in its manifest, this is a standard update mechanism for the vendor. The runtime execution is limited to local scripts provided with the project context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 10:42 PM
Security Audit — agent-trust-hub — bmad-correct-course