Back to skill

Security audit

Beads Task Tracker

Security checks for vulnerabilities and agentic risk

Overview

This skill is a plausible Git-backed task tracker, but it tells agents to make persistent repository changes and push task data through Git without enough user approval guidance.

Install only if you intentionally want Beads to manage issue data inside the repository. Before using it, confirm whether `.beads/` should be committed, whether Git hooks are acceptable, and whether `bd sync` may push task notes to the configured remote. Prefer read-only commands or local-only/stealth setup until you have reviewed the remote, branch, credentials, and hook behavior.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:9
Finding

Unpinned and Locally Unauditable External Executable Dependencies

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Warning
Location
SKILL.md:54
Finding

Automatic Installation of Persistent Git Hooks During Initialization

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:127
Finding

Mandatory Synchronization Can Commit and Push Repository Data Without Per-Operation Approval

Content
View full analysis
--title "New title" --description "New desc"` - **Run `bd sync`** at end of session to flush changes to git ``` ```bash ### Git Sync ```bash bd sync # Export → commit → pull → import → push bd hooks install # Install git hooks for auto-sync ``` The daemon auto-syncs with 30s debounce. Use `bd sync` to force immediate sync. ``` ```markdown ## Session End Checklist Before ending a session: ```bash bd sync # Flush all changes bd ready --json # Show next work for handoff ``` ``` ### Technical Analysis The Skill characterizes `bd sync` as a required end-of-session operation and describes it as a sequence that exports data, creates a commit, pulls remote changes, imports data, and pushes to a Git remote. This behavior exceeds a purely local “flush” operation. Issue records may contain task descriptions, implementation notes, design information, discovered defects, assignment details, or other sensitive planning data. If `.beads/` is tracked, mandatory synchronization can transmit that information to the configured Git remote without a separate preview or approval step. The same documentation also states that a daemon performs automatic synchronization with a 30-second debounce. Automatic and mandatory synchronization reduce the opportunity to inspect pending files, commits, merge effects, and the destination remote before repository state is changed. There is no evidence that the destination is attacker-controlled or that `bd` intentionally exfiltrates data. The risk arises from gra ...[truncated 1623 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description is broad enough to trigger on generic task-management language, which can cause the agent to invoke this skill in contexts where repository mutation is unnecessary or unsafe. Because the skill performs state-changing operations such as initializing .beads/, installing hooks, and syncing via git, unintended invocation increases the chance of accidental workspace modification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The quick-start and workflow sections instruct agents to run commands that write project data and bd init explicitly auto-installs hooks, but the documentation does not clearly warn that these operations modify the repository and local git behavior. An agent following this skill could therefore make persistent changes without clear user awareness or confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The git sync section describes bd sync as performing export, commit, pull, import, and push, but it lacks an explicit warning that this may contact remote repositories and publish local changes. In an agent setting, this is more dangerous because an automatic or routine end-of-session bd sync could leak task data, create commits, or push unintended changes to shared infrastructure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.