T08 · Insecure Dependencies
- Location
SKILL.md:9- Finding
Unpinned and Locally Unauditable External Executable Dependencies
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a plausible Git-backed task tracker, but it tells agents to make persistent repository changes and push task data through Git without enough user approval guidance.
Install only if you intentionally want Beads to manage issue data inside the repository. Before using it, confirm whether `.beads/` should be committed, whether Git hooks are acceptable, and whether `bd sync` may push task notes to the configured remote. Prefer read-only commands or local-only/stealth setup until you have reviewed the remote, branch, credentials, and hook behavior.
SKILL.md:9Unpinned and Locally Unauditable External Executable Dependencies
SKILL.md:54Automatic Installation of Persistent Git Hooks During Initialization
SKILL.md:127Mandatory Synchronization Can Commit and Push Repository Data Without Per-Operation Approval
The skill description is broad enough to trigger on generic task-management language, which can cause the agent to invoke this skill in contexts where repository mutation is unnecessary or unsafe. Because the skill performs state-changing operations such as initializing .beads/, installing hooks, and syncing via git, unintended invocation increases the chance of accidental workspace modification.
The quick-start and workflow sections instruct agents to run commands that write project data and bd init explicitly auto-installs hooks, but the documentation does not clearly warn that these operations modify the repository and local git behavior. An agent following this skill could therefore make persistent changes without clear user awareness or confirmation.
The git sync section describes bd sync as performing export, commit, pull, import, and push, but it lacks an explicit warning that this may contact remote repositories and publish local changes. In an agent setting, this is more dangerous because an automatic or routine end-of-session bd sync could leak task data, create commits, or push unintended changes to shared infrastructure.
No suspicious patterns detected.