openspec-archive-change

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from CLI-generated instructions, task files, and specification deltas which could theoretically contain malicious directives. It mitigates this risk with robust behavioral instructions that mandate treating external guidance as advisory, resolving conflicts in favor of built-in logic, and strictly forbidding the verbatim copying of external text into the workspace. \n
  • Ingestion points: openspec instructions output, tasks.md, and delta specifications.\n
  • Boundary markers: None.\n
  • Capability inventory: File system modification (mv, mkdir) and openspec CLI commands.\n
  • Sanitization: Explicit constraints against following conflicting instructions or copying external text.\n- [COMMAND_EXECUTION]: The skill utilizes shell commands (mkdir, mv) and the openspec CLI to manage change archives. These operations are performed using paths dynamically retrieved from the openspec status JSON output, ensuring that file system actions are confined to the validated project and change roots.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 12:16 PM
Security Audit — agent-trust-hub — openspec-archive-change