bmad-review
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
uv runto execute scripts for customization and metrics collection. Specifically, it executes_bmad/scripts/resolve_customization.pyfrom the project root andscripts/word_metrics.pyfrom the skill root. It also invokes system version-control tools (e.g.,git) to generate diffs for review.\n- [DYNAMIC_EXECUTION]: Thecustomize.tomlconfiguration enables the execution of literal instructions through theactivation_steps_prepend,activation_steps_append, andon_completefields. Additionally, the skill dynamically loads and executes lens-specific instructions via subagents.
Audit Metadata