BMAD work can lose traceability between requirements, reviews, tests, and closure decisions. This skill maps BMAD artifacts to RVTF records while preserving host ownership, evidence quality, and review boundaries.
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Agent request
Review the Skillstore skill "adapting-rvtf-to-bmad" from https://skillstore.io/skills/solohic-adapting-rvtf-to-bmad.md and its manifest at https://skillstore.io/api/skills/solohic-adapting-rvtf-to-bmad/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.
Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
All 36 static matches are false positives caused by Markdown inline-code spans or fenced documentation examples in SKILL.md. The skill contains no executable command mechanism, prompt injection attempt, or separate intent-level security issue.
No confirmed security findings were detected by the latest completed static and semantic audit. This does not prove the skill has no side effects.
Audited by: codex
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
solohic. (2026). adapting-rvtf-to-bmad security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/solohic-adapting-rvtf-to-bmad/audits/1
BibTeX citation
@techreport{solohic-solohic-adapting-rvtf-to-bmad-2026,
author = {solohic},
title = {adapting-rvtf-to-bmad security audit report (audit version 1)},
institution = {Skillstore},
year = {2026},
number = {1},
url = {https://skillstore.io/skills/solohic-adapting-rvtf-to-bmad/audits/1},
note = {Author version unspecified}
}
CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "adapting-rvtf-to-bmad security audit report (audit version 1)"
version: "unspecified"
type: report
authors:
- name: "solohic"
date-released: "2026-09-19"
url: "https://skillstore.io/skills/solohic-adapting-rvtf-to-bmad/audits/1"
identifiers:
- type: other
value: "skillstore:solohic-adapting-rvtf-to-bmad:audit:1"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this scoreEvidence Confidence: Medium
55
Architecture
85
Maintainability
87
Content
65
Community
91
Spec Compliance
What You Can Build
Plan Story Verification
Map a BMAD Story and its acceptance criteria to RVTF requirements, journeys, verification methods, and evidence targets before implementation.
Audit Review Coverage
Check whether adversarial, edge-case, and verification-gap reviews preserve finding identity, required roles, evidence, and host triage decisions.
Assess Epic Closure
Evaluate a BMAD retrospective using declared criteria, Story status, revisions, runtime evidence, gaps, and the RVTF completion gate.
Try These Prompts
Start a Trace Map
Map this BMAD Story to RVTF requirements, acceptance items, journeys, and journey steps. Identify missing IDs and evidence targets.
Review Acceptance Evidence
Review this Story acceptance evidence. Separate item evidence from path evidence, identify unsupported claims, and list the smallest verification gaps.
Challenge Review Scope
Audit this BMAD review record for untraced scope, unsupported verified claims, missing review-batch coverage, lost deferred gaps, and unauthorized remediation.
Assess Closure Readiness
Assess this Epic or direct change against RVTF closure rules. Preserve host status, distinguish proposed actions from approved work, and report evidence gaps and required owner decisions.
Best Practices
Use the actual closure boundary when mapping BMAD artifacts to RVTF scopes.
Keep host status, RVTF closure, evidence validity, and current test claims separate.
Preserve finding identity and review history before grouping surviving findings.
Avoid
Do not treat Story completion, Build completion, or retrospective completion as proof of RVTF closure.
Do not reuse evidence to remove mandatory host gates or claim current tests pass.
Do not convert deferred findings or advisory remediation into authorized work.
Frequently Asked Questions
What does this skill connect?
It connects BMAD scopes and lifecycle records to RVTF requirements, acceptance items, journeys, evidence, reviews, gaps, and closure rules.
Does it run BMAD commands?
No. It provides mapping and review guidance. It does not invoke builds, stories, tests, reviews, or orchestrator actions.
Can a Story prove RVTF closure?
No. Story completion remains host status. RVTF closure requires trace evidence and its own completion gate.
How should direct changes be mapped?
Map one actual direct change to an appropriate RVTF Unit. Do not fabricate Story ownership or update sprint status without a real Story key.
What evidence does review require?
Review should preserve finding identity, verify claimed consequences, record required roles, and distinguish item evidence from journey path evidence.
When should this mapping be re-audited?
Re-audit it whenever BMAD Story, Build, review, triage, or orchestrator behavior changes from the pinned host revision.