bmad-ux-designer
Pass
Audited by Gen Agent Trust Hub on May 5, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local utility scripts (
wcag-checklist.sh,responsive-breakpoints.sh,contrast-check.py). These scripts are bundled with the skill and perform benign informational tasks related to UX design and accessibility. They do not perform network operations or access sensitive system files. - [EXTERNAL_DOWNLOADS]: The
accessibility-guide.mddocumentation mentions several well-known industry-standard tools for automated accessibility testing, such aspa11y,axe-core/cli, andLighthouse. These are provided as external references for the user and are not automatically installed or executed by the skill itself. - [DATA_EXFILTRATION]: No network operations or access to sensitive user data (such as credentials, SSH keys, or environment variables) were found. The skill operates locally on project documentation and outputs markdown artifacts.
- [PROMPT_INJECTION]: The skill instructions do not contain any attempts to override model safety filters or bypass system instructions. It includes robust language guard logic to ensure consistency in communication and document output.
Audit Metadata