bmad-review

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses uv run to execute scripts for customization and metrics collection. Specifically, it executes _bmad/scripts/resolve_customization.py from the project root and scripts/word_metrics.py from the skill root. It also invokes system version-control tools (e.g., git) to generate diffs for review.\n- [DYNAMIC_EXECUTION]: The customize.toml configuration enables the execution of literal instructions through the activation_steps_prepend, activation_steps_append, and on_complete fields. Additionally, the skill dynamically loads and executes lens-specific instructions via subagents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 06:11 PM
Security Audit — agent-trust-hub — bmad-review