bmad-prd

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses uv run to execute local utility scripts such as memlog.py, resolve_customization.py, and resolve_config.py located within the project's _bmad/scripts/ directory. These are used for maintenance tasks like logging decisions and resolving configurations.
  • [COMMAND_EXECUTION]: The validation workflow includes an instruction to open a generated HTML report in the system's default browser using platform-specific commands like open, xdg-open, or start.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and summarize large amounts of external, untrusted content including web research, customer transcripts, and competitor documentation. This data ingestion creates a surface for indirect prompt injection attacks.
  • Ingestion points: User-provided verbal context, product briefs, external research, and transcripts (Discovery section).
  • Boundary markers: Uses subagents for extraction to isolate processing, but lacks explicit sanitization of the extracted text before interpolation.
  • Capability inventory: File system writes, local script execution via uv run, browser invocation, and network research.
  • Sanitization: No specific evidence of escaping or sanitizing data interpolated into internal commands or prompts.
  • [EXTERNAL_DOWNLOADS]: The skill mentions external dependencies and setup steps using npx and GitHub repositories. These resources are associated with the skill's author and represent normal functional requirements.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 09:14 PM
Security Audit — agent-trust-hub — bmad-prd