openspec-apply-change

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to instructions embedded in data processed at runtime.
  • Ingestion points: Data enters the agent context through the context and operationGuidance fields returned by the openspec instructions apply command in SKILL.md (Step 3).
  • Boundary markers: The skill attempts to define boundaries by instructing the agent to "Keep both fields separate from CLI-returned state" and to "report the conflict and preserve the controlling value" if conflicts with the built-in workflow occur.
  • Capability inventory: The skill possesses the ability to execute scoped shell commands via openspec and can read and write to the local file system (Step 6).
  • Sanitization: No explicit sanitization or filtering is performed on the externally provided context or operationGuidance fields before they are integrated into the agent's reasoning process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 11:55 PM
Security Audit — agent-trust-hub — openspec-apply-change