bmad-creative-intelligence

Pass

Audited by Gen Agent Trust Hub on May 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements structured workflows for ideation and research using local templates and documentation. No malicious patterns or security risks were identified.
  • [COMMAND_EXECUTION]: Local shell scripts in the scripts/ directory (scamper-prompts.sh, swot-template.sh, research-sources.sh) are used to generate text-based prompts. These scripts are benign and do not perform unauthorized system modifications or network exfiltration.
  • [EXTERNAL_DOWNLOADS]: The documentation and scripts reference several legitimate, well-known external research sources (e.g., Gartner, Statista, GitHub). These references are informational and do not involve the download of executable code or untrusted assets.
  • [PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection (Category 8) because it ingests untrusted data from user-provided constraints and external web research results into its context for synthesis. 1. Ingestion points: User-provided problem statements and market constraints (defined in SKILL.md); external web content retrieved during research. 2. Boundary markers: Absent; the skill does not use specific delimiters to encapsulate untrusted external data. 3. Capability inventory: File reading (docs/bmad/), file writing (brainstorm.md, research-deep.md), and network operations (WebSearch, WebFetch) described across SKILL.md and research-methods.md. 4. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
May 5, 2026, 08:07 AM
Security Audit — agent-trust-hub — bmad-creative-intelligence