openspec-context-loading
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous templates for shell commands (including
find,grep,cat,awk,sed, andbc) to allow the agent to navigate and search the local file system. These commands are scoped to thespec/directory and are used for extracting metadata and content from documentation files. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from external markdown files, which creates a vulnerability surface where malicious instructions embedded in project specs could influence agent behavior.
- Ingestion points: Markdown files (
spec.md,proposal.md,tasks.md) located within thespec/specs/andspec/changes/directories (SKILL.md). - Boundary markers: None identified. The skill directly reads and summarizes the content of these files without specific delimiters or instructions to ignore embedded commands.
- Capability inventory: The skill uses
find,grep, andcatto locate and read files, and includes logic for text processing and basic arithmetic viabc. - Sanitization: None identified. Content is ingested as raw text for summarization and discovery.
Audit Metadata