information-architecture-beads

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the beads-cli package and its official GitHub repository for manual installation if the tool is not found on the system.
  • [COMMAND_EXECUTION]: The skill uses the bd command-line interface to initialize issue tracking and manage tasks within the repository based on the architectural findings.
  • [PROMPT_INJECTION]: The skill identifies an attack surface for indirect prompt injection by ingesting repository files (routes, page layouts, and menus). This finding is associated with the ingestion of untrusted local data without explicit boundary markers, though the skill's capabilities are restricted to documentation and task creation.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 04:52 PM
Security Audit — agent-trust-hub — information-architecture-beads