bmad-product-brief

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest untrusted external data, including user-provided memos, decks, transcripts, and Slack threads, as well as results from web-research subagents. This creates a surface for indirect prompt injection where malicious instructions embedded in these sources could influence the agent's behavior during the brief creation or validation process.
  • Ingestion points: Source materials (memos, decks, transcripts, Slack threads) and web search digests are ingested in the ## Discovery phase.
  • Boundary markers: The skill instructions specify that subagents should provide "relevance-filtered extracts" to the parent context, which provides some isolation, but no explicit XML-style delimiters or "ignore" instructions are used for the final brief drafting.
  • Capability inventory: The skill can execute shell commands via uv run, write to the filesystem (brief.md, addendum.md, .memlog.md), perform network operations (web research), and invoke external MCP tools for handoffs.
  • Sanitization: No explicit sanitization or escaping of the ingested text is described beyond the extraction process.
  • [DYNAMIC_EXECUTION]: The skill dynamically executes Python scripts (resolve_customization.py, memlog.py) using the uv run command. These scripts are passed arguments derived from the conversation context (e.g., product names or decision gists). Additionally, the skill executes a sequence of instructions defined in the on_complete configuration field at the end of the workflow.
  • [COMMAND_EXECUTION]: The skill uses the uv run pattern to execute local scripts within the project environment for configuration resolution and audit logging. While these scripts are part of the vendor's framework, the interpolation of user-influenced strings into command arguments represents a potential vector for command injection if the underlying scripts do not handle arguments securely.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:08 AM
Security Audit — agent-trust-hub — bmad-product-brief