ralph-tui-create-beads
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external PRD content to generate task descriptions for autonomous agents, creating a potential surface for indirect prompt injection.
- Ingestion points: The skill takes a markdown PRD or text as input (processed in Step 1 and the Output Format section).
- Boundary markers: The skill specifically instructs the use of single-quoted HEREDOC syntax (
<<'EOF') to wrap PRD content, which acts as a boundary to prevent the shell from interpreting characters within the PRD as commands. - Capability inventory: The skill generates
bd createandbd dep addcommands that modify the.beads/beads.jsonlfile. - Sanitization: The documentation emphasizes the importance of single-quoted delimiters to prevent shell interpretation of backticks, variables, and subshells from the source text.
- [COMMAND_EXECUTION]: The skill generates shell commands using the
bdCLI tool to create epics, child beads, and manage dependencies based on the input PRD.
Audit Metadata