bmad-agent-ux-designer
Warn
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a Python script directly from the project root during the activation sequence.
- Evidence:
SKILL.mdcontains the instructionuv run {project-root}/_bmad/scripts/resolve_customization.py. This executes code found at a path that may be controlled by a potentially untrusted project repository. - [DYNAMIC_EXECUTION]: The skill is designed to execute sequences of instructions provided through external configuration files.
- Evidence: The activation flow in
SKILL.md(Steps 2 and 7) involves executing all entries in theactivation_steps_prependandactivation_steps_appendarrays. These steps are loaded from project-specific TOML files, allowing for the execution of arbitrary logic defined outside the skill itself. - [DATA_EXFILTRATION]: The skill provides a feature to automatically load the contents of files into the agent's session context based on configuration.
- Evidence: Step 4 of the activation process in
SKILL.mdparsespersistent_facts. Any entry starting withfile:is interpreted as a file path or glob, and the referenced file's contents are read into the agent's context. This could be used to expose sensitive local files if a malicious configuration is provided. - [INDIRECT_PROMPT_INJECTION]: The skill's behavior and access patterns are highly dependent on configuration files stored in the user's project directory.
- Ingestion points:
{project-root}/_bmad/custom/bmad-agent-ux-designer.toml,{project-root}/_bmad/bmm/config.yaml, and the user override version of the TOML file. - Capability inventory: The skill can execute commands, run dynamic steps, and read files.
- Boundary markers: There are no explicit boundaries or 'ignore' instructions provided when the skill interpolates configuration data or file contents into its context.
- Sanitization: The skill does not validate or sanitize the paths or instructions loaded from the project configuration before execution or ingestion.
Audit Metadata