bmad-bmm-analyst

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to process external business data, stakeholder inputs, and market research, which inherently involves an indirect prompt injection surface.\n
  • Ingestion points: Stakeholder interviews, market research data, and user-provided project scenarios as described in SKILL.md.\n
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands in external data.\n
  • Capability inventory: The skill defines analytical workflows (Market Analysis, Requirements Discovery) but does not include any code, scripts, or tool definitions in the skill package.\n
  • Sanitization: No data validation or sanitization steps are specified for information retrieved from external sources.\n- [SAFE]: No security issues were detected in the skill instructions. The content consists entirely of business analysis methodology, documentation standards, and process guidelines. The skill does not include any executable scripts, remote dependencies, or sensitive resource access.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 08:05 AM
Security Audit — agent-trust-hub — bmad-bmm-analyst