openspec-propose
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external instructions and templates retrieved from the openspec CLI tool, which are used to guide the agent's behavior and file generation.
- Ingestion points: The JSON output from commands like
openspec instructionsandopenspec statusis used to define artifact content and build order. - Boundary markers: The skill provides instructions to the agent to treat fields like
contextandrulesas internal constraints rather than including them in the final output artifacts. - Capability inventory: The skill utilizes the
Bashtool to run theopenspecCLI and write files to the local file system. - Sanitization: No explicit sanitization logic is provided for the data returned by the CLI tool before it is interpreted by the agent.
- [COMMAND_EXECUTION]: The skill constructs shell commands dynamically using variables such as change names provided by the user and store or artifact IDs discovered during the workflow.
- Evidence: The skill defines command templates like
openspec new change "<name>"andopenspec status --change "<name>" --json --store "<id>". These executions are restricted to theopenspecCLI by theallowed-toolsconfiguration.
Audit Metadata