bmad

Warn

Audited by Socket on Mar 20, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
.DS_Store

The fragment is a binary/resource bundle rather than executable source code. There is insufficient evidence of explicit malicious activity in the visible portion, but embedded/packed assets pose a non-trivial supply-chain risk. A deeper binary analysis (unpacking blobs, inspecting embedded scripts, and dynamic behavior) and provenance verification are required to rule out covert payloads. Recommend obtaining a manifest, checksums, or signed packaging and performing binary-level inspection or decryption/decompression analysis.

Confidence: 72%Severity: 60%
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the workflow capabilities are mostly consistent with the stated orchestration purpose, and file/script access is broadly proportionate for a local development workflow. The main concern is the transitive installation model: it instructs the agent to install another remote skill from a third-party GitHub repo, extending trust to unreviewed instructions under the agent's permissions. No clear credential harvesting, exfiltration endpoint, or overtly malicious behavior is present in the provided skill text.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Mar 20, 2026, 07:05 AM
Package URL
pkg:socket/skills-sh/JEO-tech-ai%2Foh-my-gods%2Fbmad%2F@b3c1ba76fd6ef804f41c211b3e50842fa569893a
Security Audit — socket — bmad