bmad-agent-ux-designer

Warn

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a Python script directly from the project root during the activation sequence.
  • Evidence: SKILL.md contains the instruction uv run {project-root}/_bmad/scripts/resolve_customization.py. This executes code found at a path that may be controlled by a potentially untrusted project repository.
  • [DYNAMIC_EXECUTION]: The skill is designed to execute sequences of instructions provided through external configuration files.
  • Evidence: The activation flow in SKILL.md (Steps 2 and 7) involves executing all entries in the activation_steps_prepend and activation_steps_append arrays. These steps are loaded from project-specific TOML files, allowing for the execution of arbitrary logic defined outside the skill itself.
  • [DATA_EXFILTRATION]: The skill provides a feature to automatically load the contents of files into the agent's session context based on configuration.
  • Evidence: Step 4 of the activation process in SKILL.md parses persistent_facts. Any entry starting with file: is interpreted as a file path or glob, and the referenced file's contents are read into the agent's context. This could be used to expose sensitive local files if a malicious configuration is provided.
  • [INDIRECT_PROMPT_INJECTION]: The skill's behavior and access patterns are highly dependent on configuration files stored in the user's project directory.
  • Ingestion points: {project-root}/_bmad/custom/bmad-agent-ux-designer.toml, {project-root}/_bmad/bmm/config.yaml, and the user override version of the TOML file.
  • Capability inventory: The skill can execute commands, run dynamic steps, and read files.
  • Boundary markers: There are no explicit boundaries or 'ignore' instructions provided when the skill interpolates configuration data or file contents into its context.
  • Sanitization: The skill does not validate or sanitize the paths or instructions loaded from the project configuration before execution or ingestion.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 20, 2026, 07:08 AM
Security Audit — agent-trust-hub — bmad-agent-ux-designer