openspec-propose

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external instructions and templates retrieved from the openspec CLI tool, which are used to guide the agent's behavior and file generation.
  • Ingestion points: The JSON output from commands like openspec instructions and openspec status is used to define artifact content and build order.
  • Boundary markers: The skill provides instructions to the agent to treat fields like context and rules as internal constraints rather than including them in the final output artifacts.
  • Capability inventory: The skill utilizes the Bash tool to run the openspec CLI and write files to the local file system.
  • Sanitization: No explicit sanitization logic is provided for the data returned by the CLI tool before it is interpreted by the agent.
  • [COMMAND_EXECUTION]: The skill constructs shell commands dynamically using variables such as change names provided by the user and store or artifact IDs discovered during the workflow.
  • Evidence: The skill defines command templates like openspec new change "<name>" and openspec status --change "<name>" --json --store "<id>". These executions are restricted to the openspec CLI by the allowed-tools configuration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 07:49 AM
Security Audit — agent-trust-hub — openspec-propose