navigate
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from an external work graph, creating an attack surface where malicious instructions embedded in task titles or comments could influence agent behavior.
- Ingestion points: The skill retrieves external content using
bd show <epic>,bd children, andbd comments <bead>as described in the 'Observe' section ofSKILL.md. - Boundary markers: There are no explicit instructions or delimiters defined to prevent the agent from following natural language instructions found within the bead data.
- Capability inventory: The skill has the ability to create and modify the graph using
bd createandbd update, and can delegate tasks to other skills likeOrchestrateorPlan. - Sanitization: The instructions do not specify any sanitization, filtering, or validation of the content retrieved from the 'bd' tool before it is used to determine the next 'wave' of work.
Audit Metadata