openspec-apply-change
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
openspecCLI tool through Bash to perform project management tasks, such as listing changes, checking status, and retrieving implementation instructions. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external sources that could contain untrusted instructions.
- Ingestion points: The skill reads data from the JSON output of
openspec instructions apply(specifically thecontextandoperationGuidancefields) and accesses the content of multiple files referenced in thecontextFilesarray. - Boundary markers: The skill contains explicit instructions to treat external
contextandoperationGuidanceas advisory prompt-level inputs that must be kept separate from the CLI-managed state, progress, and tasks. - Capability inventory: The skill has the capability to execute the
openspecCLI and perform file system read/write operations to implement tasks and update task checklists. - Sanitization: The instructions require the agent to report conflicts between the external guidance and the controlling CLI inputs, ensuring that the CLI-controlled values (like blocked states) take precedence.
Audit Metadata