Agent governance and AI-TDD control plane for requirement-contract-driven Main Agent orchestration, built on BMAD + Spec-Kit
LPM flags this version as an AI-agent control-surface risk. Installing the package automatically alters the consumer project's Cursor agent configuration and installs executable hooks. Those hooks inject package-controlled policy into agent sessions and can block tool use.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
_bmad/cursor/hooks/subagent-result-summary.cjsView on unpkg · L5Package source references shell execution.
_bmad/skills/governed-feature-delivery/scripts/run-phase.mjsView on unpkg · L864Package source references dynamic require/import behavior.
bin/bmad-speckit.jsView on unpkg · L4Package source references weak cryptographic algorithms.
node_modules/bmad-speckit/dist/services/install-surface-manifest.jsView on unpkg · L43Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/init-to-root.jsView on unpkg · L8Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
Package source invokes a package manager install command at runtime.
node_modules/@bmad-speckit/runtime-emit/dist/run-auditor-host.cjsView on unpkg · L15461Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
_bmad/core/skills/bmad-distillator/scripts/tests/test_analyze_sources.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
_bmad/core/skills/bmad-distillator/scripts/tests/test_analyze_sources.pyView on unpkgPackage contains source files above the normal full-analysis size ceiling.
node_modules/@bmad-speckit/runtime-emit/dist/emit-runtime-policy.cjsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
_bmad/skills/requirements-contract-authoring/assets/mermaid/mermaid.min.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/bmad-speckit/_bmad/runtime/hooks/runtime-policy-inject-core.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/bmad-speckit/_bmad/claude/hooks/worktree-create-sibling.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/bmad-speckit/_bmad/skills/goal-execution-contract-generator/scripts/check-docs-review-dependency.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/bmad-speckit/_bmad/skills/goal-subcontract-execution-package-generator/scripts/close-completed-campaign.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/bmad-speckit/_bmad/skills/requirements-contract-authoring/assets/mermaid/mermaid.min.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/bmad-speckit/_bmad/skills/requirements-contract-authoring/scripts/reverse_audit_contract.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/bmad-speckit/_bmad/claude/hooks/subagent-result-summary.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/bmad-speckit/_bmad/runtime/hooks/governance-packet-hard-closeout.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/bmad-speckit/_bmad/runtime/hooks/pre-continue-check.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/bmad-speckit/_bmad/shared/goal-contract/scripts/extract-goal-contract-profile.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/bmad-speckit/_bmad/skills/requirements-contract-authoring/scripts/ingest-confirmation-event.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/bmad-speckit/_bmad/skills/requirements-contract-authoring/scripts/write-critical-auditor-no-new-gap-response.jsView on unpkgThis report applies to bmad-speckit-sdd-flow@2.2.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
_bmad/cursor/hooks/subagent-result-summary.cjsView on unpkg · L5Package source references shell execution.
_bmad/skills/governed-feature-delivery/scripts/run-phase.mjsView on unpkg · L864Package source references dynamic require/import behavior.
bin/bmad-speckit.jsView on unpkg · L4Package source references weak cryptographic algorithms.
node_modules/bmad-speckit/dist/services/install-surface-manifest.jsView on unpkg · L43Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/init-to-root.jsView on unpkg · L8Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
Package source invokes a package manager install command at runtime.
node_modules/@bmad-speckit/runtime-emit/dist/run-auditor-host.cjsView on unpkg · L15461Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
_bmad/core/skills/bmad-distillator/scripts/tests/test_analyze_sources.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
_bmad/core/skills/bmad-distillator/scripts/tests/test_analyze_sources.pyView on unpkgPackage contains source files above the normal full-analysis size ceiling.
node_modules/@bmad-speckit/runtime-emit/dist/emit-runtime-policy.cjsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
_bmad/skills/requirements-contract-authoring/assets/mermaid/mermaid.min.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/bmad-speckit/_bmad/runtime/hooks/runtime-policy-inject-core.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/bmad-speckit/_bmad/claude/hooks/worktree-create-sibling.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/bmad-speckit/_bmad/skills/goal-execution-contract-generator/scripts/check-docs-review-dependency.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/bmad-speckit/_bmad/skills/goal-subcontract-execution-package-generator/scripts/close-completed-campaign.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/bmad-speckit/_bmad/skills/requirements-contract-authoring/assets/mermaid/mermaid.min.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/bmad-speckit/_bmad/skills/requirements-contract-authoring/scripts/reverse_audit_contract.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/bmad-speckit/_bmad/claude/hooks/subagent-result-summary.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/bmad-speckit/_bmad/runtime/hooks/governance-packet-hard-closeout.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/bmad-speckit/_bmad/runtime/hooks/pre-continue-check.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/bmad-speckit/_bmad/shared/goal-contract/scripts/extract-goal-contract-profile.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/bmad-speckit/_bmad/skills/requirements-contract-authoring/scripts/ingest-confirmation-event.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/bmad-speckit/_bmad/skills/requirements-contract-authoring/scripts/write-critical-auditor-no-new-gap-response.jsView on unpkg