openspec-apply

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill describes a workflow that ingests data from local files (tasks.md, design.md) to perform operations like writing code and running tests. This presents a potential surface for indirect prompt injection if those input files contain instructions intended to deviate the agent from its intended behavior.\n
  • Ingestion points: Local project artifacts including tasks.md, design.md, and the specs/ directory.\n
  • Boundary markers: The instructions do not define specific delimiters for separating task data from system instructions.\n
  • Capability inventory: The workflow includes writing and modifying code files and executing test commands.\n
  • Sanitization: No validation or sanitization logic is specified for the task content processed by the agent.\n- [EXTERNAL_DOWNLOADS]: The skill contains reference links to documentation on GitHub.\n
  • Evidence: Links to github.com/Fission-AI/OpenSpec for command and concept documentation. These are standard documentation references to a well-known service.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 04:11 PM
Security Audit — agent-trust-hub — openspec-apply