bmad-ux

Warn

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses uv run to execute local Python scripts (resolve_customization.py and memlog.py) located within the project's _bmad/scripts/ directory to handle configuration and decision logging.
  • [COMMAND_EXECUTION]: The skill utilizes platform-specific commands such as open (macOS), xdg-open (Linux), and start (Windows) to automatically launch generated HTML files in the user's browser.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data (PRDs, brand decks, sketches) provided by the user or found in the project workspace. This data is used by subagents to populate design specifications, creating a surface where malicious instructions within these documents could potentially influence agent behavior.
  • Ingestion points: Processes files from {planning_artifacts}/, imports/ folder, and user-provided documents.
  • Boundary markers: No explicit delimiters or warnings to ignore embedded instructions are present in the prompts that process this data.
  • Capability inventory: The skill has access to shell execution (uv run, open), file writing, and subagent spawning.
  • Sanitization: The skill does not describe any specific sanitization or filtering of the content extracted from external documents.
  • [DYNAMIC_EXECUTION]: The skill dynamically generates HTML and Excalidraw artifacts based on the conversation and user inputs, which are then used as part of the visual identity and experience documentation.
  • [EXTERNAL_DOWNLOADS]: The skill references and links to design specifications and tools from Google Labs and Google Stitch. These are recognized as trusted services.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 20, 2026, 07:08 AM
Security Audit — agent-trust-hub — bmad-ux