br

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on executing the br (Beads Rust) binary and bv (Beads Viewer) tool for issue management. These are local CLI tools specifically intended for the skill's primary purpose.
  • [REMOTE_CODE_EXECUTION]: While the br upgrade command exists for self-updating the tool, it is documented as a standard administrative function and does not fetch or execute arbitrary remote scripts during normal operation.
  • [DATA_EXFILTRATION]: The skill manages project issues locally in a .beads/ directory. Synchronization is performed explicitly by the agent using standard git commands (git push), which is the intended behavior for a distributed issue tracker.
  • [INDIRECT_PROMPT_INJECTION]: As an issue tracker, the skill processes untrusted data from issue descriptions and comments. However, it emphasizes structured JSON output (--json) and provides clear boundary markers in its documentation to mitigate accidental instruction obedience.
  • [TRUST_SCOPE_RULE]: The skill is authored by 'Dicklesworthstone'. All references to br and bv tools, as well as the 'Dicklesworthstone' vendor identity, are treated as safe vendor-owned resources for this project management context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:12 AM
Security Audit — agent-trust-hub — br