openspec-context-loading

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides numerous templates for shell commands (including find, grep, cat, awk, sed, and bc) to allow the agent to navigate and search the local file system. These commands are scoped to the spec/ directory and are used for extracting metadata and content from documentation files.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from external markdown files, which creates a vulnerability surface where malicious instructions embedded in project specs could influence agent behavior.
  • Ingestion points: Markdown files (spec.md, proposal.md, tasks.md) located within the spec/specs/ and spec/changes/ directories (SKILL.md).
  • Boundary markers: None identified. The skill directly reads and summarizes the content of these files without specific delimiters or instructions to ignore embedded commands.
  • Capability inventory: The skill uses find, grep, and cat to locate and read files, and includes logic for text processing and basic arithmetic via bc.
  • Sanitization: None identified. Content is ingested as raw text for summarization and discovery.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 06:06 PM