openspec-review

Pass

Audited by Gen Agent Trust Hub on Apr 2, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by ingesting untrusted markdown artifacts from the filesystem into the agent's context.
  • Ingestion points: openspec/project.md, proposal.md, design.md, tasks.md, tests.md, and specs/*.md are read as inputs for review.
  • Boundary markers: The skill does not implement specific delimiters or 'ignore' instructions for the ingested content.
  • Capability inventory: The agent has access to the Bash and Agent tools while processing this data.
  • Sanitization: No sanitization or validation of the markdown file content is performed prior to analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 2, 2026, 06:18 AM
Security Audit — agent-trust-hub — openspec-review