beads
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent/user to install the
beadsCLI tool usingbrew install beadsor by downloading it from thegithub.com/gastownhall/beadsrepository. These are standard methods for tool distribution on well-known platforms. - [COMMAND_EXECUTION]: The skill relies on the execution of the
bd(Beads) CLI utility for all its operations. This utility performs file system modifications within the.beadsdirectory and manages network communications for database synchronization. - [INDIRECT_PROMPT_INJECTION]: The skill presents a surface for indirect prompt injection due to its integration with external data sources.
- Ingestion points: Untrusted data enters the agent context via
bd sync(pulling from GitHub, GitLab, Jira, Linear, or Azure DevOps),bd import(reading local JSONL files), andbd create -f(parsing markdown plans). - Boundary markers: The tool stores data in a structured Git-like database (Dolt), but the fields themselves (descriptions, notes, and acceptance criteria) contain unstructured natural language text that the agent is expected to follow.
- Capability inventory: The skill allows the agent to write files, perform network sync operations, and manage persistent memory across sessions.
- Sanitization: Documentation in
references/sync.mdnotes that external tracker content is sanitized for terminal display, but specific prompt sanitization for agent consumption is not explicitly described.
Audit Metadata