bmad-product-manager

Pass

Audited by Gen Agent Trust Hub on May 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or safety guidelines bypasses were found in the skill's instructions or metadata.
  • [COMMAND_EXECUTION]: The skill utilizes local scripts (scripts/prioritize.py and scripts/validate-prd.sh) for mathematical calculations and document validation. Analysis of these scripts confirms they perform safe, local-only operations without network access or sensitive file interaction.
  • [PROMPT_INJECTION]: The skill ingests discovery artifacts and project configuration to generate requirements documents. While this defines an attack surface for indirect prompt injection, the risk is negligible as the skill lacks high-privilege capabilities such as network exfiltration or arbitrary system command execution.
Audit Metadata
Risk Level
SAFE
Analyzed
May 5, 2026, 08:07 AM
Security Audit — agent-trust-hub — bmad-product-manager