skillZs
★ LIVE SKILL TAGS ★
>>> LIVE SKILLS INDEX <<<
* OPEN SOURCE *
NO LOGIN, NO TRACKING
※ REAL INSTALL DATA ※
← back to all skills
bmad-code-org/bmad-method358 installs

bmad-document-project

Deprecated — forwards to bmad-project-context. Use when the user says "document this project" or "generate project docs"

How do I install this agent skill?

npx skills add https://github.com/bmad-code-org/bmad-method --skill bmad-document-project
view source ↗

Is this agent skill safe to install?

  • Gen Agent Trust Hubfail

    This skill documents projects by scanning their source code and directory structure. It contains a high-risk pattern where it executes a Python script located within the project being documented. If a user attempts to document a malicious or untrusted project, this script could execute arbitrary code on the user's system. Additionally, the skill's 'Exhaustive Scan' mode reads every line of project source code, making it vulnerable to indirect prompt injection from malicious code or comments.

  • Socketpass

    No alerts

  • Snykpass

    Risk: LOW · No issues

  • ZeroLeakspass

    Score: 93/100 · 2 sections analyzed

What does this agent skill do?

DEPRECATED — forwards to bmad-project-context

Tell the user two things.

First: this skill is deprecated. Generating documentation volume about a codebase made agents worse, not better — agents read code more accurately than prose describing code, and the generated set was stale on arrival. bmad-project-context owns what remains useful: a small verified block in the repo's AGENTS.md carrying what the code cannot say — required policy, conventions that differ from defaults, what running the project takes that no config file states, and known pitfalls.

Second, so they are not surprised by what they get: the deeper "explain this system, its rationale and its history" material is a different altitude and is not part of that block. It is coming as its own capability. If that is what they were after, say so plainly rather than producing a thin substitute.

Then invoke bmad-project-context with setup intent, forwarding the user's original request and any paths or documents they supplied, verbatim. It takes the workflow from here.

Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.

<a href="https://skillzs.dev/skills/bmad-code-org/bmad-method/bmad-document-project">View bmad-document-project on skillZs</a>