bmad-agent-marketing-pricing

Pass

Audited by Gen Agent Trust Hub on Apr 3, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to set up the environment by installing the agent-browser tool and downloading required Playwright binaries. These resources originate from Vercel Labs' official repositories.
  • [COMMAND_EXECUTION]: The skill utilizes shell commands to manage browser automation sessions, capture screenshots, and extract text from target web pages as part of its competitive research functionality.
  • [PROMPT_INJECTION]: The skill operates as a research tool that ingests data from external websites, which is a common surface for indirect prompt injection. It retrieves full text bodies from competitor domains to perform pricing analysis.
  • Ingestion points: External competitor pricing pages accessed via agent-browser.
  • Boundary markers: Not explicitly defined in the retrieval commands.
  • Capability inventory: File system writes (screenshots and research markdown files), network access (browser-based research).
  • Sanitization: Content is processed to extract pricing data for strategic reporting.
  • [DYNAMIC_EXECUTION]: The skill implements a selective loading mechanism that resolves local reference file paths dynamically using a central CSV index (frameworks-index.csv) to manage context window efficiency.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 3, 2026, 11:27 AM