bv

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides workflow examples where the agent is instructed to parse JSON output from the bv tool (which reads from .beads/beads.jsonl) and use the resulting values directly in shell commands. Specifically, the 'Agent Workflow Pattern' demonstrates capturing a task ID from bv output and passing it to the br claim command. If the project data file is malicious or contains specifically crafted identifiers (e.g., containing shell metacharacters), it could lead to command injection or unintended agent behavior.
  • Ingestion points: The skill ingests data from the local .beads/beads.jsonl file via the bv command-line utility.
  • Boundary markers: The skill encourages the use of structured JSON output (--robot-triage) to separate data from instructions, but the suggested bash scripts do not include validation steps for the extracted data before shell interpolation.
  • Capability inventory: The agent is expected to execute shell commands (bv, br, jq, echo), perform local file reads/writes, and potentially interact with version control systems (git).
  • Sanitization: No explicit sanitization, escaping, or validation of the NEXT_TASK variable is present in the provided workflow examples.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 09:43 AM
Security Audit — agent-trust-hub — bv