br
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on executing the
br(Beads Rust) binary andbv(Beads Viewer) tool for issue management. These are local CLI tools specifically intended for the skill's primary purpose. - [REMOTE_CODE_EXECUTION]: While the
br upgradecommand exists for self-updating the tool, it is documented as a standard administrative function and does not fetch or execute arbitrary remote scripts during normal operation. - [DATA_EXFILTRATION]: The skill manages project issues locally in a
.beads/directory. Synchronization is performed explicitly by the agent using standardgitcommands (git push), which is the intended behavior for a distributed issue tracker. - [INDIRECT_PROMPT_INJECTION]: As an issue tracker, the skill processes untrusted data from issue descriptions and comments. However, it emphasizes structured JSON output (
--json) and provides clear boundary markers in its documentation to mitigate accidental instruction obedience. - [TRUST_SCOPE_RULE]: The skill is authored by 'Dicklesworthstone'. All references to
brandbvtools, as well as the 'Dicklesworthstone' vendor identity, are treated as safe vendor-owned resources for this project management context.
Audit Metadata