bmad-agent-ux-designer
Warn
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill is designed to execute arbitrary shell commands defined in the
activation_steps_prependandactivation_steps_appendarrays found in thecustomize.tomlconfiguration file and its project-level overrides ({skill-name}.tomland{skill-name}.user.toml). This allows the agent to run potentially dangerous operations during the initialization phase based on the contents of local configuration files. - [DYNAMIC_EXECUTION]: The skill uses
uv runto execute Python scripts located within the project's own directory structure ({project-root}/_bmad/scripts/resolve_customization.pyandresolve_config.py). This pattern executes code derived from the project environment to resolve customization and configuration at runtime. - [INDIRECT_PROMPT_INJECTION]: The skill features multiple ingestion points for external data that could influence agent behavior:
- Ingestion points: Step 4 in
SKILL.mdloads content from files specified inpersistent_facts(including glob patterns), and Step 5 searches for and loads existing project documents (briefs, specs, research, etc.). - Boundary markers: The instructions do not define clear delimiters or "ignore embedded instructions" wrappers for the ingested file content.
- Capability inventory: The skill has access to shell execution via activation steps and subprocess execution via
uv runinSKILL.md(Steps 1, 2, 5, 7). - Sanitization: There is no evidence of sanitization or validation performed on the ingested file contents before they are added to the agent's context.
- [EXTERNAL_DOWNLOADS]: The skill references external resources for installing recommended capabilities (e.g.,
github:bmad-code-org/BMAD-METHOD/skills). These references point to the vendor's own infrastructure and are used as instructions for the user or agent to expand functionality.
Audit Metadata