bmad-auto

Warn

Audited by Socket on May 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly coherent with its stated purpose as an implementation orchestrator, but it has a large action surface: persistent sub-agents, transitive invocation of many other skills, repository-wide reads, code changes, tests, Docker/infrastructure validation, and autonomous workflow progression. There is no clear credential theft, third-party proxying, or malicious exfiltration, so this is not malware; the main concerns are medium operational risk, transitive trust in downstream skills, and prompt-injection exposure from project content combined with write/exec capabilities.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
May 10, 2026, 11:19 AM
Package URL
pkg:socket/skills-sh/bmad-labs%2Fskills%2Fbmad-auto%2F@5bc41797adad46da3e5984c907f88a2e9b528357
Security Audit — socket — bmad-auto