openspec-explore
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from the local codebase and configuration files which could contain untrusted data. 1. Ingestion points: Data enters the agent context through CLI commands like openspec list, status, and instructions, as well as project files such as config.yaml. 2. Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions when reading these external files. 3. Capability inventory: The skill uses the Bash tool restricted to the openspec CLI for reading project data and writing specific OpenSpec artifacts. 4. Sanitization: No explicit validation or filtering logic is described for the content read from the codebase or CLI outputs.
- [DYNAMIC_EXECUTION]: The skill dynamically adjusts its actions based on metadata provided by the openspec CLI. Evidence: The skill is instructed to follow template and instruction fields from CLI outputs, including potentially invoking other skills or commands if artifact creation is delegated.
Audit Metadata