bmad-product-brief
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
uv runutility to execute local scripts (resolve_customization.py,resolve_config.py, andmemlog.py) stored in the{project-root}/_bmad/scripts/directory as part of its standard activation and logging workflow. - [DYNAMIC_EXECUTION]: The agent is instructed to dynamically execute steps defined in configuration variables (
activation_steps_prepend,activation_steps_append) and load data from file paths specified in{workflow.persistent_facts}, creating a flexible execution environment. - [EXTERNAL_DOWNLOADS]: The skill references a remote repository for its core functionality and suggests that users install missing components via
npx skills add bmad-code-org/BMAD-METHOD, which involves downloading code from a vendor source. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection by processing external source materials. Ingestion points: The Discovery section explicitly invites 'brain dumps' and processes external source material such as Slack threads, meeting transcripts, and research subagent digests. Boundary markers: The instructions lack explicit delimitation or warnings to ignore instructions embedded within the ingested source material. Capability inventory: The skill has the ability to execute shell commands (via
uv run), write to the local filesystem (briefs and logs), and invoke MCP tools for external data transfer. Sanitization: No sanitization or filtering logic is provided for the aggregated external data. - [DATA_EXFILTRATION]: The skill is designed to route finalized artifacts to external systems like Confluence or Notion using MCP tools defined in the
external_handoffsconfiguration, representing a managed data movement capability.
Audit Metadata