bmad-shared — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited bmad-shared (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Provide shared workflow state contracts and helper scripts for all BMAD skills.
Enforce language selection separately for chat responses and generated artifacts.
Chat language (communication_language) fallback order:
language.communication_language from bmad/project.yamlEnglishRules for chat responses:
Artifact language (document_output_language) fallback order:
language.document_output_language from bmad/project.yamlEnglishRules for generated artifacts:
System shall followed by non-English text)API, SLA, KPI, OAuth, WCAG)Before executing shared helper workflows, read REFERENCE.md first. Treat REFERENCE.md as required context for state semantics and update rules.
config-readstatus-updatenext-recommendationworkflows.registry.yamlREFERENCE.mdhelpers.mdCurrent scripts:
bash scripts/load-project-config.sh bmad/project.yaml bash scripts/load-global-config.sh bash scripts/update-workflow-status.sh --workflow product_brief --status-file bmad/workflow-status.yaml bash scripts/next-workflow.sh bmad/workflow-status.yamlCompatibility wrappers:
scripts/load-config.sh -> wrapper to load-project-config.shscripts/update-status.sh -> wrapper to update-workflow-status.shscripts/check-phase.sh -> wrapper to next-workflow.shyq v4+ for all YAML reads and writes~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.