openspec-new-change

Pass

Audited by Gen Agent Trust Hub on Apr 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides instructions for orchestrating local development workflows using the openspec CLI. All operations are local to the user's environment.
  • [COMMAND_EXECUTION]: The skill executes openspec commands using user-provided input for the change name. It includes a specific guardrail requiring the name to be in kebab-case, which serves as a validation step to prevent shell metacharacter injection.
  • [PROMPT_INJECTION]: No evidence of prompt injection, role-play bypasses, or safety instruction overrides were found. The instructions are task-oriented and respect operational boundaries.
  • [DATA_EXFILTRATION]: No network operations, credential access, or sensitive file reads were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 2, 2026, 12:09 AM
Security Audit — agent-trust-hub — openspec-new-change