openspec-archive-change

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses mkdir and mv commands to manage the directory structure for archived changes.
  • [COMMAND_EXECUTION]: It invokes the openspec CLI tool to interact with the project workflow.
  • [PROMPT_INJECTION]: The agent reads content from tasks.md and project specification files to determine archival readiness. Ingestion points: tasks.md and files in openspec/changes/<name>/specs/. Boundary markers: None. Capability inventory: shell commands (mkdir, mv) and CLI execution. Sanitization: None.
  • [DATA_EXFILTRATION]: Accesses and moves project-specific files within the openspec/ directory. All actions are confined to the local filesystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 12:04 PM
Security Audit — agent-trust-hub — openspec-archive-change