bmad-ux

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses uv run to execute local project scripts for configuration resolution, customization, and memory logging (e.g., resolve_config.py, resolve_customization.py, and memlog.py in the _bmad/scripts/ directory). It also invokes platform-specific commands such as open (macOS), xdg-open (Linux), and start (Windows) to open generated HTML design artifacts in the user's web browser for interactive review.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data including user-provided PRDs, product briefs, and visual references (Figma exports, sketches, brand decks) to extract design decisions. While these are managed through subagents, the ingestion of external content into the agent context presents an inherent risk of indirect instruction injection from the source material.
  • [EXTERNAL_DOWNLOADS]: Instructions are provided to install additional tools from the vendor's official repository using npx skills add bmad-code-org/BMAD-METHOD if the environment is not already configured. This download targets the vendor's own infrastructure and is part of the intended setup process.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 10:30 PM
Security Audit — agent-trust-hub — bmad-ux