bv
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides workflow examples where the agent is instructed to parse JSON output from the
bvtool (which reads from.beads/beads.jsonl) and use the resulting values directly in shell commands. Specifically, the 'Agent Workflow Pattern' demonstrates capturing a task ID frombvoutput and passing it to thebr claimcommand. If the project data file is malicious or contains specifically crafted identifiers (e.g., containing shell metacharacters), it could lead to command injection or unintended agent behavior. - Ingestion points: The skill ingests data from the local
.beads/beads.jsonlfile via thebvcommand-line utility. - Boundary markers: The skill encourages the use of structured JSON output (
--robot-triage) to separate data from instructions, but the suggested bash scripts do not include validation steps for the extracted data before shell interpolation. - Capability inventory: The agent is expected to execute shell commands (
bv,br,jq,echo), perform local file reads/writes, and potentially interact with version control systems (git). - Sanitization: No explicit sanitization, escaping, or validation of the
NEXT_TASKvariable is present in the provided workflow examples.
Audit Metadata