bmad-prd
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
uv runto execute local utility scripts such asmemlog.py,resolve_customization.py, andresolve_config.pylocated within the project's_bmad/scripts/directory. These are used for maintenance tasks like logging decisions and resolving configurations. - [COMMAND_EXECUTION]: The validation workflow includes an instruction to open a generated HTML report in the system's default browser using platform-specific commands like
open,xdg-open, orstart. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and summarize large amounts of external, untrusted content including web research, customer transcripts, and competitor documentation. This data ingestion creates a surface for indirect prompt injection attacks.
- Ingestion points: User-provided verbal context, product briefs, external research, and transcripts (Discovery section).
- Boundary markers: Uses subagents for extraction to isolate processing, but lacks explicit sanitization of the extracted text before interpolation.
- Capability inventory: File system writes, local script execution via
uv run, browser invocation, and network research. - Sanitization: No specific evidence of escaping or sanitizing data interpolated into internal commands or prompts.
- [EXTERNAL_DOWNLOADS]: The skill mentions external dependencies and setup steps using
npxand GitHub repositories. These resources are associated with the skill's author and represent normal functional requirements.
Audit Metadata