BeadsSAFE
Beads - A memory upgrade for your coding agent
Overview
Beads - A memory upgrade for your coding agent
399746604c3dOBSERVED · 2026-10-03What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: beads description: Use when working in a repository that uses bd or Beads for durable project task tracking, issue dependencies, blocker management, multi-session handoff, or shared work memory. Trigger when the user asks to find ready work, claim or close tasks, create follow-up work, inspect blockers, recover project context, or choose between local planning and persistent project tracking. --- # Beads Use Beads as the shared project task system. Local plans, scratch files, and personal memories are useful, but they are not the durable source of truth for project work. ## First Step Run: ```bash bd prime ``` If that prints nothing, check whether the repository has an active Beads workspace: ```bash bd where ``` ## Preferred Route Use the `bd` CLI when shell access is available. It is the most compact and direct Beads interface. ## Core CLI Workflow 1. Find work: ```bash bd ready bd list --status=open bd list --status=in_progress ``` 2. Inspect before editing: ```bash bd show <id> ``` 3. Claim work atomically: ```bash bd update <id> --claim ``` 4. Create durable follow-up work when implementation reveals new tasks: ```bash bd create "Short title" --description="Why this exists and what needs to be done" --type=task --priority=2 ``` 5. Close completed work: ```bash bd close <id> --reason="Completed" ``` ## What Belongs In Beads Use Beads for: - shared project tasks - blockers and dependencies - discovered follow-up work - work that must survive thread reset, compaction, or handoff - status that another person or agent should be able to resume Use agent-local planning tools only for the current turn's execution checklist. Do not treat them as shared project state. ## Rules - Do not create markdown TODO files as the source of truth when Beads is available. - Do not use `bd edit`; it opens an interactive editor. Use `bd update` flags instead. - Prefer `--json` when parsing `bd` output programmatically. - If hooks are installed, `bd prime` may already be injected. Run it manually when context is missing. - Do not auto-close or mutate tasks unless the work is actually complete.
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
399746604c3dfull audit observations/trust-audit/skill/gastownhall__beads.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-03 | 399746604c3d | SAFE | B | 89 | first audit |
Questions
What does the Beads skill do?
Beads - A memory upgrade for your coding agent
Is Beads safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Beads access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (399746604c3d), read on 2026-10-03. The repository is watched, and a new audit runs when it changes — this is the first audit.