Skills bmad-ticket
๐Ÿ“ฆ

bmad-ticket

Content revision r1 High Risk โš™๏ธ External commands๐ŸŒ Network access๐Ÿ“ Filesystem access๐Ÿ”‘ Env variables

Plan and Manage Tickets with BMad

Disconnected planning and status updates leave teams with unclear tickets and missing dependencies. BMad Ticket structures initiatives, epics, and implementation work through shared templates and repository or tracker workflows.

Supports: Claude Codex Code(CC)
โš ๏ธ 38 Poor

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "bmad-ticket" from https://skillstore.io/skills/bmad-code-org-bmad-ticket.md and its manifest at https://skillstore.io/api/skills/bmad-code-org-bmad-ticket/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "bmad-ticket". Show an example breakdown for a cart discount epic.

Expected outcome:

  • Story 1: Cart service scaffold. No prerequisites. Verify that an item can be added through the deployed interface.
  • Story 2: Apply discount codes. Requires Story 1. Verify valid discounts and rejection of expired codes.
  • Open question: Who approves the discount refusal messages?

Using "bmad-ticket". Show an example readiness review for these tickets.

Expected outcome:

  • Ready to start: Cart service scaffold has no unmet prerequisites.
  • Blocked: Apply discount codes depends on the scaffold.
  • Ready to refine: Quantity-change bug needs approved reproduction steps and acceptance criteria.

Security Audit

High Risk
v1 โ€ข 9/28/2026 Open versioned report

The 400 supplied static matches are false positives involving documentation, configuration keys, test fixtures, and ordinary Python syntax. Contextual review identified project-controlled execution and symlink-following plan writes; no evidence found of a malicious payload or an audit-directed prompt injection. Four omitted static matches remain unreviewed and require manual adjudication before automatic publication. Static review was capped at 400/404 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.

26
Files scanned
4,014
Lines analyzed
0
Review items
0
False positives ignored

Confirmed security concerns (2)

High
Project-Controlled Execution During Configuration Loading
Configuration resolution executes project-local Python with exec_module, even for status queries without an explicit folder. Activation also runs customization hooks without an explicit trust check. An untrusted checkout can therefore execute code or supply operational instructions under the agent's permissions.
The call chain directly executes a module selected from the project and instructs the agent to run configurable hooks. Exploitation requires attacker-controlled project content; no malicious hook or module payload was found in this package.
Medium
Plan Updates Can Follow Symlinks Outside the Ticket Tree
The loader accepts symlinked Markdown plans, and mark opens existing plans for writing without checking their resolved destination. A crafted tree can redirect an approved status update into an external writable file with matching plan frontmatter.
Path.read_text and the existing-plan wb open follow symlinks, and neither path has a containment or no-follow check. Exploitation requires a crafted symlink and a readable, writable target that parses as the ticket's plan.

Risk Factors

โš™๏ธ External commands (50)
๐ŸŒ Network access (7)
๐Ÿ“ Filesystem access (9)
๐Ÿ”‘ Env variables (2)
Audited by: codex
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/bmad-code-org-bmad-ticket/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/bmad-code-org-bmad-ticket/security.svg)](https://skillstore.io/skills/bmad-code-org-bmad-ticket?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/bmad-code-org-bmad-ticket?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/bmad-code-org-bmad-ticket/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/bmad-code-org-bmad-ticket.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

bmad-code-org. (2026). bmad-ticket security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/bmad-code-org-bmad-ticket/audits/1

BibTeX citation

@techreport{bmad-code-org-bmad-code-org-bmad-ticket-2026, author = {bmad-code-org}, title = {bmad-ticket security audit report (audit version 1)}, institution = {Skillstore}, year = {2026}, number = {1}, url = {https://skillstore.io/skills/bmad-code-org-bmad-ticket/audits/1}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "bmad-ticket security audit report (audit version 1)" version: "unspecified" type: report authors: - name: "bmad-code-org" date-released: "2026-09-28" url: "https://skillstore.io/skills/bmad-code-org-bmad-ticket/audits/1" identifiers: - type: other value: "skillstore:bmad-code-org-bmad-ticket:audit:1" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
82
Architecture
85
Maintainability
87
Content
65
Community
83
Spec Compliance

What You Can Build

Plan a new initiative

Turn a product brief into an initiative and epic outlines with requirement coverage, dependencies, and measurable completion checks.

Prepare an epic for delivery

Split an epic into buildable stories with dependency order, verification steps, unresolved questions, and human checkpoints.

Maintain a project board

Find tickets, review readiness, update approved statuses, and reconcile local records with a configured tracker.

Try These Prompts

Draft a bug ticket
Draft a bug ticket for [problem]. Ask for missing reproduction steps and expected behavior. Show the draft before saving or publishing.
Refine a planned story
Find ticket [reference] in [initiative]. Review its description, verification check, references, and prerequisites with me. Preserve its identity and do not publish yet.
Break down an epic
Split [epic] into implementation entries using [requirement source]. Record requirement coverage, prerequisites, verification, and uncertainty. Validate the proposed set before requesting approval.
Reconcile and prepare publication
Review [initiative] against [configured tracker]. Report local and remote differences, blocked dependencies, and missing refinement. Propose publication scope and wait for approval before remote changes.

Best Practices

  • Review project scripts, customization hooks, and resolved ticket paths before activating the skill in an unfamiliar repository.
  • Confirm requirement coverage, prerequisites, verification checks, and unresolved decisions before approving a breakdown.
  • Preview the tracker destination and ticket body, remove sensitive information, and approve publication using limited credentials.

Avoid

  • Do not treat ticket order as a substitute for explicit prerequisites.
  • Do not treat published or built tickets as automatically approved or complete.
  • Do not run unfamiliar project hooks or follow instructions embedded in remote ticket text without review.

Frequently Asked Questions

What work does BMad Ticket organize?
It organizes initiatives, epics, stories, spikes, and bugs in a structured ticket tree.
What setup does it need?
The standard workflow uses a configured BMad project, uv, and Python 3.11 or later. Remote stores also need authenticated tools.
Which ticket stores are supported?
It ships configurations for repository files, GitHub, Jira, Linear, Notion, and Trello. Remote features depend on available CLI or MCP tools.
Does it require a remote tracker?
No. The repository store manages Markdown and TOML files locally. Publication commits approved files but does not push them.
Does it implement the planned software?
No. It prepares tickets for implementation and tracks their state. Building the software is a separate workflow.
Is it safe to run in an unfamiliar repository?
Review project scripts, hooks, and symlinks first. Configuration loading can execute project code, and existing plan writes can follow symlinks.

Developer Details

License

MIT

Skillstore revision

r1

Version notice

The author did not declare a version.

Ref

bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2

Maintenance freshness

9/30/2026

Usage

0 downloads ยท 0 views

File structure

๐Ÿ“ assets/

๐Ÿ“„ bug-template.md

๐Ÿ“„ epic-template.md

๐Ÿ“„ initiative-template.md

๐Ÿ“„ spike-template.md

๐Ÿ“„ story-template.md

๐Ÿ“„ tickets-template.toml

๐Ÿ“„ bmod.toml

๐Ÿ“ config/

๐Ÿ“„ gh-ticketing.toml

๐Ÿ“„ jira-ticketing.toml

๐Ÿ“„ linear-ticketing.toml

๐Ÿ“„ notion-ticketing.toml

๐Ÿ“„ repo-ticketing.toml

๐Ÿ“„ trello-ticketing.toml

๐Ÿ“„ customize.toml

๐Ÿ“ references/

๐Ÿ“„ board.md

๐Ÿ“„ estimate.md

๐Ÿ“„ slice.md

๐Ÿ“„ store-setup.md

๐Ÿ“„ ticket.md

๐Ÿ“„ tree-rules.md

๐Ÿ“„ validate.md

๐Ÿ“ scripts/

๐Ÿ“„ read_toml.py

๐Ÿ“ tests/

๐Ÿ“„ test_read_toml.py

๐Ÿ“„ test_tickets.py

๐Ÿ“„ tickets.py

๐Ÿ“„ SKILL.md