journey-map-beads
Pass
Audited by Gen Agent Trust Hub on May 19, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the beads-cli package via pip and provides a link to the tool's public GitHub repository.
- [COMMAND_EXECUTION]: The skill uses the bd command-line tool to initialize tracking environments and create structured issues based on journey mapping findings.
- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it ingests and processes user-controlled project files. 1. Ingestion points: Reads from project routes, components, documentation, and existing prototype flows. 2. Boundary markers: No delimiters or specific instructions to ignore embedded commands are present in the skill definition. 3. Capability inventory: The agent has the capability to execute shell commands via the Beads CLI and create new documentation files. 4. Sanitization: No explicit sanitization or validation of the findings is performed before they are interpolated into the shell command arguments used for issue creation.
Audit Metadata