bmad-prd
Warn
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses system shell commands (
open,xdg-open, orstart) to automatically open generated HTML validation reports in the host's default web browser, as documented inreferences/validate.md. - [DYNAMIC_EXECUTION]: The skill relies on the execution of Python scripts located at
{project-root}/_bmad/scripts/(e.g.,memlog.py,resolve_customization.py) via theuv runcommand. These scripts are critical for configuration resolution and state management throughout the PRD lifecycle. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: The skill is designed to ingest and process a wide variety of external, potentially untrusted documents during the 'Discovery' phase, including product briefs, research documents, and customer transcripts (detailed in
SKILL.md). - Boundary markers: The skill instructions emphasize an 'Extract, don't ingest' approach using subagents, which acts as a structural boundary to reduce the risk of instructions within external data being directly obeyed by the parent agent.
- Capability inventory: The skill possesses capabilities to execute local scripts, run shell commands, write files to the local workspace, and perform network operations via external MCP tool handoffs (e.g., uploading to Confluence or Notion).
- Sanitization: The instructions do not define specific sanitization, filtering, or escaping protocols for the content extracted from external sources before it is used to generate the final PRD or other artifacts.
Audit Metadata