openspec-onboard

Pass

Audited by Gen Agent Trust Hub on Apr 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill's behavior is consistent with its stated purpose of developer onboarding. All operations are performed locally using the OpenSpec CLI and standard shell utilities.
  • [COMMAND_EXECUTION]: The skill executes local commands like openspec status, git log, and openspec archive to manage project state. These actions are intended for tool operation and do not involve remote communication.
  • [PROMPT_INJECTION]: The skill reads the local codebase to suggest tasks, which is an indirect prompt injection surface. This risk is managed by the skill's design, which requires user confirmation for all suggested tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 17, 2026, 01:18 AM