openspec-apply-change

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the openspec CLI tool through Bash to perform project management tasks, such as listing changes, checking status, and retrieving implementation instructions.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external sources that could contain untrusted instructions.
  • Ingestion points: The skill reads data from the JSON output of openspec instructions apply (specifically the context and operationGuidance fields) and accesses the content of multiple files referenced in the contextFiles array.
  • Boundary markers: The skill contains explicit instructions to treat external context and operationGuidance as advisory prompt-level inputs that must be kept separate from the CLI-managed state, progress, and tasks.
  • Capability inventory: The skill has the capability to execute the openspec CLI and perform file system read/write operations to implement tasks and update task checklists.
  • Sanitization: The instructions require the agent to report conflicts between the external guidance and the controlling CLI inputs, ensuring that the CLI-controlled values (like blocked states) take precedence.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 07:48 AM
Security Audit — agent-trust-hub — openspec-apply-change