BMad Master

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface by ingesting user-supplied data to generate project configurations.
  • Ingestion points: User inputs for project_name, project_type, and project_level are collected during the /workflow-init process.
  • Boundary markers: There are no explicit delimiters or boundary markers mentioned to isolate user-provided strings from the rest of the configuration instructions.
  • Capability inventory: The skill has file-writing capabilities, specifically creating and writing to bmad/config.yaml and docs/bmm-workflow-status.yaml.
  • Sanitization: The instructions do not define any sanitization, validation, or escaping logic for the project metadata before it is written to the file system.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 04:49 PM
Security Audit — agent-trust-hub — BMad Master