openspec-archive-change
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill retrieves context, guidance, and rules from external data sources via the
openspec instructionscommand in Steps 1 and 4, which could potentially be influenced by malicious repository content. \n - Ingestion points: Data is ingested from the output of
openspec instructions archiveandopenspec instructions specs. \n - Boundary markers: The skill does not define specific delimiters for these external inputs but instructs the agent to treat them as non-authoritative. \n
- Capability inventory: The agent has the ability to execute
openspeccommands, use theopenspec-sync-specsworkflow, and perform file operations likemkdirandmv. \n - Sanitization: The skill contains explicit guardrails requiring the agent to report conflicts between external guidance and built-in rules, ignore inapplicable advice, and avoid verbatim copying of these instructions into output files. \n
- [COMMAND_EXECUTION]: The skill uses shell commands (
mkdir,mv) for local file management. The scope of these commands is limited to paths dynamically provided by theopenspectool's status metadata, minimizing the risk of arbitrary path manipulation.
Audit Metadata