openspec-design
Pass
Audited by Gen Agent Trust Hub on Apr 2, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted data from proposal.md to generate design documents, creating a surface for indirect prompt injection.
- Ingestion points: The design and maintain commands read content from openspec/changes/{id}/proposal.md (SKILL.md).
- Boundary markers: Absent. No delimiters or instructions to ignore embedded commands are used.
- Capability inventory: The skill has file-read and file-write capabilities in the local directory.
- Sanitization: Absent. No filtering or validation of external content is specified.
Audit Metadata