beads
Fail
Audited by Socket on Mar 9, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
Overall, the Beads skill presents a coherent, purpose-aligned toolset for persistent memory and task tracking within AI agent workflows using Dolt as the storage backend. The install path via a Brew tap is reasonable for developer tooling, and there are no obvious malicious patterns such as arbitrary code execution, credential harvesting, or data exfiltration to untrusted endpoints. Some concerns remain around trust in the third-party Brew tap and explicit credential handling documentation, but these are standard for developer tooling and do not indicate malicious intent. The footprint appears proportionate to its stated purpose with no evident dangerous data flows.
Confidence: 98%
Audit Metadata