grill-with-change

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes content from local specification files which represents a surface for indirect prompt injection. Ingestion points: Reads artifact content from proposal.md, design.md, tasks.md, and spec files during the 'Locate And Inspect The Change' and 'Phase Transaction' steps. Boundary markers: None identified in the prompt instructions. Capability inventory: Local file system write operations and execution of 'openspec' CLI tools. Sanitization: None. The risk is minimized by the skill's operational constraint to ask exactly one user-facing question at a time and wait for confirmation before closing any phase or committing changes.
  • [COMMAND_EXECUTION]: The skill makes use of the 'openspec' CLI utility to interact with the project repository. Commands are restricted to listing, status checking, and validation tasks (such as 'openspec list', 'openspec status', and 'openspec validate') that are consistent with the skill's described development workflow and do not involve unauthorized privilege levels or suspicious parameters.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 06:06 PM
Security Audit — agent-trust-hub — grill-with-change