beads-orchestrate
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The orchestrator ingests data from external, potentially untrusted sources including bead notes via
bd show, repository documentation (AGENTS.md,CLAUDE.md), and reports from sub-agents. This data is then used to plan waves of work and is interpolated directly into prompts for implementation agents. - Ingestion points: Data is loaded from the environment and external files in Phase 0 (
bd prime,AGENTS.md), Phase 1 (bd show), and Phase 4 (agent reports). - Boundary markers: The skill does not explicitly instruct the agent to use delimiters or security warnings when including external note content in sub-agent prompts, although it does treat notes as 'binding decisions'.
- Capability inventory: The skill has access to the
Bashtool for command execution and theAgenttool for spawning sub-agents with their own tool access. - Sanitization: There is no instruction to sanitize or escape external data before it is relayed to the user or passed to other agents.
- [DYNAMIC_EXECUTION]: The skill dynamically generates complex instructions for implementation agents by populating a template (
references/agent-prompt.md) with data retrieved during execution, such as bead requirements, binding decisions, and project memories. - [COMMAND_EXECUTION]: The orchestrator and its sub-agents use
Bashto perform various local operations including git repository management (git worktree,git fetch,git reset), container management (ddev,lando,docker-compose), and project-specific CLI tool interaction (bd). - [EXTERNAL_DOWNLOADS]: Implementation agents are instructed to perform fresh dependency installations (e.g.,
npm ci,npm install) as part of their workspace setup, which involves fetching packages from public registries.
Audit Metadata