bearcli
Pass
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
bearclicommand-line tool to manage Bear notes. It performs standard operations like searching, reading, and editing notes, which is the primary purpose of the skill.\n- [PROMPT_INJECTION]: The skill is potentially vulnerable to indirect prompt injection because it reads note content. If a note contains malicious instructions, the agent might execute them.\n - Ingestion points: SKILL.md (via
bearcli cat,bearcli show, andbearcli searchcommands)\n - Boundary markers: Absent\n
- Capability inventory: Shell command execution (
bearcli) across all workflows\n - Sanitization: Absent
Audit Metadata