bmad-deep-recon
What this skill does
Research and analysis tool for generating and processing deep-research prompts, processing research reports, and running recon through web fan-out. It supports various research types (market, domain,
github/bmad-code-org - Code Injection - 51.7k stars
Threat analysis
Skill info
pkg:github/bmad-code-org/BMAD-METHOD@890fcda?skill=bmad-deep-reconAssessments (2)
Code Injection
Code Injection via local-llm-review
scripts/recon_kit.py
The code imports 'un' (likely a typo or incomplete import) which could be a vector for code injection if not properly validated.Malicious URL
Malicious URL via local-llm-review
scripts/tests/test_recon_kit.py
The test data contains a malicious URL: 'javascript:alert(1)' in the source appendix table. This could be used to inject malicious scripts if not properly sanitized.Badge
Add the Anomity scan badge for bmad-deep-recon to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of bmad-deep-recon? Report an issue or request a rescan.




