openspec-archive-change

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves context, guidance, and rules from external data sources via the openspec instructions command in Steps 1 and 4, which could potentially be influenced by malicious repository content. \n
  • Ingestion points: Data is ingested from the output of openspec instructions archive and openspec instructions specs. \n
  • Boundary markers: The skill does not define specific delimiters for these external inputs but instructs the agent to treat them as non-authoritative. \n
  • Capability inventory: The agent has the ability to execute openspec commands, use the openspec-sync-specs workflow, and perform file operations like mkdir and mv. \n
  • Sanitization: The skill contains explicit guardrails requiring the agent to report conflicts between external guidance and built-in rules, ignore inapplicable advice, and avoid verbatim copying of these instructions into output files. \n
  • [COMMAND_EXECUTION]: The skill uses shell commands (mkdir, mv) for local file management. The scope of these commands is limited to paths dynamically provided by the openspec tool's status metadata, minimizing the risk of arbitrary path manipulation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 07:49 AM
Security Audit — agent-trust-hub — openspec-archive-change