bmad-product-brief
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest untrusted external data, including user-provided memos, decks, transcripts, and Slack threads, as well as results from web-research subagents. This creates a surface for indirect prompt injection where malicious instructions embedded in these sources could influence the agent's behavior during the brief creation or validation process.
- Ingestion points: Source materials (memos, decks, transcripts, Slack threads) and web search digests are ingested in the
## Discoveryphase. - Boundary markers: The skill instructions specify that subagents should provide "relevance-filtered extracts" to the parent context, which provides some isolation, but no explicit XML-style delimiters or "ignore" instructions are used for the final brief drafting.
- Capability inventory: The skill can execute shell commands via
uv run, write to the filesystem (brief.md,addendum.md,.memlog.md), perform network operations (web research), and invoke external MCP tools for handoffs. - Sanitization: No explicit sanitization or escaping of the ingested text is described beyond the extraction process.
- [DYNAMIC_EXECUTION]: The skill dynamically executes Python scripts (
resolve_customization.py,memlog.py) using theuv runcommand. These scripts are passed arguments derived from the conversation context (e.g., product names or decision gists). Additionally, the skill executes a sequence of instructions defined in theon_completeconfiguration field at the end of the workflow. - [COMMAND_EXECUTION]: The skill uses the
uv runpattern to execute local scripts within the project environment for configuration resolution and audit logging. While these scripts are part of the vendor's framework, the interpolation of user-influenced strings into command arguments represents a potential vector for command injection if the underlying scripts do not handle arguments securely.
Audit Metadata