journey-map-beads

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the beads-cli package via pip and provides a link to the tool's public GitHub repository.
  • [COMMAND_EXECUTION]: The skill uses the bd command-line tool to initialize tracking environments and create structured issues based on journey mapping findings.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it ingests and processes user-controlled project files. 1. Ingestion points: Reads from project routes, components, documentation, and existing prototype flows. 2. Boundary markers: No delimiters or specific instructions to ignore embedded commands are present in the skill definition. 3. Capability inventory: The agent has the capability to execute shell commands via the Beads CLI and create new documentation files. 4. Sanitization: No explicit sanitization or validation of the findings is performed before they are interpolated into the shell command arguments used for issue creation.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 04:52 PM
Security Audit — agent-trust-hub — journey-map-beads