beads
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or security vulnerabilities were identified within the skill's instructions, metadata, or reference documentation.
- [COMMAND_EXECUTION]: The skill instructs the agent to use the
bdCLI tool and standard Unix commands (git,grep,rm) for its core functionality. These operations are appropriate for its purpose as a developer productivity tool. Potentially destructive commands, such as database reset operations, are documented with clear warnings and intended for troubleshooting purposes only. - [EXTERNAL_DOWNLOADS]: The skill documentation references official installation paths for the
bdCLI tool via legitimate package managers including npm (@beads/cli), Go (github.com/steveyegge/beads), and Homebrew. These references are presented as prerequisites for the skill and do not involve unauthorized or hidden downloads. - [PROMPT_INJECTION]: No attempts to override system instructions or bypass safety guardrails were detected. The instructions are focused on guiding the agent through task management workflows and best practices.
Audit Metadata