skills/itechmeat/llm-code/beads/Gen Agent Trust Hub

beads

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent/user to install the beads CLI tool using brew install beads or by downloading it from the github.com/gastownhall/beads repository. These are standard methods for tool distribution on well-known platforms.
  • [COMMAND_EXECUTION]: The skill relies on the execution of the bd (Beads) CLI utility for all its operations. This utility performs file system modifications within the .beads directory and manages network communications for database synchronization.
  • [INDIRECT_PROMPT_INJECTION]: The skill presents a surface for indirect prompt injection due to its integration with external data sources.
  • Ingestion points: Untrusted data enters the agent context via bd sync (pulling from GitHub, GitLab, Jira, Linear, or Azure DevOps), bd import (reading local JSONL files), and bd create -f (parsing markdown plans).
  • Boundary markers: The tool stores data in a structured Git-like database (Dolt), but the fields themselves (descriptions, notes, and acceptance criteria) contain unstructured natural language text that the agent is expected to follow.
  • Capability inventory: The skill allows the agent to write files, perform network sync operations, and manage persistent memory across sessions.
  • Sanitization: Documentation in references/sync.md notes that external tracker content is sanitized for terminal display, but specific prompt sanitization for agent consumption is not explicitly described.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 01:24 AM