bmad-create-architecture

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill executes a local Python script resolve_customization.py located in the project's internal directory {project-root}/_bmad/scripts/. This execution is used solely for merging configuration layers from defaults, team, and user settings, which is a standard part of the skill's infrastructure and does not involve downloading or executing remote code.
  • [SAFE]: The skill processes project-related documents like PRDs and UX designs. It includes a mandatory discovery protocol that lists discovered files and requires explicit user confirmation before loading them into the context, ensuring the user has oversight of the data processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 02:10 PM