openspec-explore

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from the local codebase and configuration files which could contain untrusted data. 1. Ingestion points: Data enters the agent context through CLI commands like openspec list, status, and instructions, as well as project files such as config.yaml. 2. Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions when reading these external files. 3. Capability inventory: The skill uses the Bash tool restricted to the openspec CLI for reading project data and writing specific OpenSpec artifacts. 4. Sanitization: No explicit validation or filtering logic is described for the content read from the codebase or CLI outputs.
  • [DYNAMIC_EXECUTION]: The skill dynamically adjusts its actions based on metadata provided by the openspec CLI. Evidence: The skill is instructed to follow template and instruction fields from CLI outputs, including potentially invoking other skills or commands if artifact creation is delegated.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 07:49 AM
Security Audit — agent-trust-hub — openspec-explore