bmad-review

Warn

Audited by Socket on Sep 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core review behavior is consistent with the stated purpose, and the only named external dependency (uv) appears to be official and verifiable. The main concern is that the skill executes a project-local script and configurable activation hooks, giving reviewed repositories a code-execution path that exceeds a narrowly scoped read-only review skill.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Sep 6, 2026, 06:11 PM
Package URL
pkg:socket/skills-sh/bmad-code-org%2Fbmad-method%2Fbmad-review%2F@5dfaccbe042e0d4285edd4643b9cb2fce56769edc46f031a88c5fe28193affdf
Security Audit — socket — bmad-review